mediawiki
431 tracked vulnerabilities.
CVE-2019-18611
MEDIUM
MediaWiki CheckUser <1.34 - Info Disclosure
Oct 29, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-16738
MEDIUM
MediaWiki <1.33.0 - Info Disclosure
Sep 26, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-14807
MEDIUM
MobileFrontend 1.31.0-1.33.0 - Cross-Site Scripting in Edit Summary Field
Aug 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-12470
MEDIUM
MediaWiki <= 1.32.1 - Incorrect Access Control in RevisionDelete Page
Jul 10, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-12469
MEDIUM
MediaWiki < 1.27.6 - Incorrect Access Control
Jul 10, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-12474
HIGH
MediaWiki 1.23.0-1.32.1 - Information Disclosure via Cached API Response
Jul 10, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12473
HIGH
MediaWiki 1.27.0-1.32.1 - Denial of Service via Invalid Title API Query
Jul 10, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12472
HIGH
MediaWiki 1.18.0-1.32.1 - Incorrect Access Control via API
Jul 10, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-12471
MEDIUM
MediaWiki 1.27.0-1.27.5 1.30.0-1.30.1 - Cross-Site Scripting via Non-Existent User JavaScript
Jul 10, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-12466
HIGH
MediaWiki < 1.32.1 - Cross-Site Request Forgery
Jul 10, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-12468
CRITICAL
MediaWiki 1.27.0-1.32.1 - Incorrect Access Control via Special:ChangeEmail
Jul 10, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-12467
MEDIUM
MediaWiki <1.32.1 - Info Disclosure
Jul 10, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-13258
MEDIUM
MediaWiki 1.31.0 - Unauthenticated Exposure of Sensitive Information via Missing .htaccess Files
Oct 04, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-0505
MEDIUM
MediaWiki 1.27.0-1.27.4 and 1.31.0 - Improper Authentication via BotPasswords CentralAuth Bypass
Oct 04, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-0504
MEDIUM
MediaWiki 1.27.0-1.27.4 and 1.31.0 - Information Disclosure in Special:Redirect/logid
Oct 04, 2018
CVSS 6.5
EPSS 0.02
CVE-2018-0503
MEDIUM
MediaWiki 1.27.0-1.27.4, 1.31.0 - Improper Privilege Management via Rate Limit Override
Oct 04, 2018
CVSS 4.3
EPSS 0.00
CVE-2017-20175
LOW
DaSchTour matomo-mediawiki-extension <2.4.2 - XSS
Feb 05, 2023
CVSS 2.6
EPSS 0.00
CVE-2017-0371
HIGH
MediaWiki <1.23.16, 1.24.x-1.27.x<1.27.2, 1.28.x<1.28.1 - Info Disc...
Feb 18, 2022
CVSS 7.5
EPSS 0.00
CVE-2017-0372
CRITICAL
MediaWiki < 1.23.16, 1.27.3, 1.28.2 - Parameter Injection in SyntaxHighlight Extension
Apr 13, 2018
CVSS 9.8
EPSS 0.58
CVE-2017-0370
MEDIUM
MediaWiki < 1.23.16 - Spam Blacklist Bypass via Encoded URLs in File Inclusion Syntax
Apr 13, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-0369
MEDIUM
MediaWiki < 1.23.16 - Authenticated Page Undeletion via Protection Bypass
Apr 13, 2018
CVSS 6.5
EPSS 0.00
CVE-2017-0368
MEDIUM
MediaWiki < 1.23.16 - Improper Input Validation in RawHTML Mode
Apr 13, 2018
CVSS 5.3
EPSS 0.00
CVE-2017-0367
HIGH
MediaWiki < 1.27.2 - Unsafe Temporary Directory Usage in LocalisationCache
Apr 13, 2018
CVSS 8.8
EPSS 0.01
CVE-2017-0366
MEDIUM
MediaWiki < 1.23.16 - SVG Filter Bypass via Default Attribute Values in DTD Declaration
Apr 13, 2018
CVSS 5.4
EPSS 0.00
CVE-2017-0365
MEDIUM
MediaWiki < 1.23.16, 1.27.0-1.27.2, < 1.28.1 - Cross-Site Scripting in SearchHighlighter
Apr 13, 2018
CVSS 4.7
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters