mediawiki

431 tracked vulnerabilities.

CVE-2019-18611 MEDIUM
MediaWiki CheckUser <1.34 - Info Disclosure
Oct 29, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-16738 MEDIUM
MediaWiki <1.33.0 - Info Disclosure
Sep 26, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-14807 MEDIUM
MobileFrontend 1.31.0-1.33.0 - Cross-Site Scripting in Edit Summary Field
Aug 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-12470 MEDIUM
MediaWiki <= 1.32.1 - Incorrect Access Control in RevisionDelete Page
Jul 10, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-12469 MEDIUM
MediaWiki < 1.27.6 - Incorrect Access Control
Jul 10, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-12474 HIGH
MediaWiki 1.23.0-1.32.1 - Information Disclosure via Cached API Response
Jul 10, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12473 HIGH
MediaWiki 1.27.0-1.32.1 - Denial of Service via Invalid Title API Query
Jul 10, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12472 HIGH
MediaWiki 1.18.0-1.32.1 - Incorrect Access Control via API
Jul 10, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12471 MEDIUM
MediaWiki 1.27.0-1.27.5 1.30.0-1.30.1 - Cross-Site Scripting via Non-Existent User JavaScript
Jul 10, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-12466 HIGH
MediaWiki < 1.32.1 - Cross-Site Request Forgery
Jul 10, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-12468 CRITICAL
MediaWiki 1.27.0-1.32.1 - Incorrect Access Control via Special:ChangeEmail
Jul 10, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-12467 MEDIUM
MediaWiki <1.32.1 - Info Disclosure
Jul 10, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-13258 MEDIUM
MediaWiki 1.31.0 - Unauthenticated Exposure of Sensitive Information via Missing .htaccess Files
Oct 04, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-0505 MEDIUM
MediaWiki 1.27.0-1.27.4 and 1.31.0 - Improper Authentication via BotPasswords CentralAuth Bypass
Oct 04, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-0504 MEDIUM
MediaWiki 1.27.0-1.27.4 and 1.31.0 - Information Disclosure in Special:Redirect/logid
Oct 04, 2018
CVSS 6.5
EPSS 0.02
CVE-2018-0503 MEDIUM
MediaWiki 1.27.0-1.27.4, 1.31.0 - Improper Privilege Management via Rate Limit Override
Oct 04, 2018
CVSS 4.3
EPSS 0.00
CVE-2017-20175 LOW
DaSchTour matomo-mediawiki-extension <2.4.2 - XSS
Feb 05, 2023
CVSS 2.6
EPSS 0.00
CVE-2017-0371 HIGH
MediaWiki <1.23.16, 1.24.x-1.27.x<1.27.2, 1.28.x<1.28.1 - Info Disc...
Feb 18, 2022
CVSS 7.5
EPSS 0.00
CVE-2017-0372 CRITICAL
MediaWiki < 1.23.16, 1.27.3, 1.28.2 - Parameter Injection in SyntaxHighlight Extension
Apr 13, 2018
CVSS 9.8
EPSS 0.58
CVE-2017-0370 MEDIUM
MediaWiki < 1.23.16 - Spam Blacklist Bypass via Encoded URLs in File Inclusion Syntax
Apr 13, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-0369 MEDIUM
MediaWiki < 1.23.16 - Authenticated Page Undeletion via Protection Bypass
Apr 13, 2018
CVSS 6.5
EPSS 0.00
CVE-2017-0368 MEDIUM
MediaWiki < 1.23.16 - Improper Input Validation in RawHTML Mode
Apr 13, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-0367 HIGH
MediaWiki < 1.27.2 - Unsafe Temporary Directory Usage in LocalisationCache
Apr 13, 2018
CVSS 8.8
EPSS 0.01
CVE-2017-0366 MEDIUM
MediaWiki < 1.23.16 - SVG Filter Bypass via Default Attribute Values in DTD Declaration
Apr 13, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-0365 MEDIUM
MediaWiki < 1.23.16, 1.27.0-1.27.2, < 1.28.1 - Cross-Site Scripting in SearchHighlighter
Apr 13, 2018
CVSS 4.7
EPSS 0.00