mediawiki

431 tracked vulnerabilities.

CVE-2017-0364 MEDIUM
MediaWiki < 1.23.16 - URL Redirection to Untrusted Site via Special:Search
Apr 13, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-0363 MEDIUM
MediaWiki < 1.23.16 - URL Redirection to Untrusted Site via Special:UserLogin returnto Parameter
Apr 13, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-0362 HIGH
MediaWiki < 1.23.16 - Cross-Site Request Forgery via Watchlist Mark All Pages Visited
Apr 13, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-0361 HIGH
MediaWiki < 1.23.16 - Exposure of Sensitive Information via API Log
Apr 13, 2018
CVSS 7.8
EPSS 0.00
CVE-2017-8815 HIGH
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Attribute Injection via Language Converter Glossary Rules
Nov 15, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-8814 HIGH
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Text Injection via Language Converter Rule Definition
Nov 15, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-8812 MEDIUM
MediaWiki <1.27.4, <1.28.3, <1.29.2 - XSS
Nov 15, 2017
CVSS 5.3
EPSS 0.01
CVE-2017-8811 MEDIUM
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - HTML Mangling via Raw Message Parameter Expansion
Nov 15, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-8810 HIGH
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Username Enumeration via Login Error Messages
Nov 15, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-8809 CRITICAL
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Reflected File Download via api.php
Nov 15, 2017
CVSS 9.8
EPSS 0.18
CVE-2017-8808 MEDIUM
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Cross-Site Scripting via Non-Standard URL Escaping
Nov 15, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6337 HIGH
MediaWiki 1.27.x - Improper Access Control via UserGetRights Function
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-6336 MEDIUM
MediaWiki <1.23.15, <1.26.x-1.26.4, <1.27.x-1.27.1 - Auth Bypass
Apr 20, 2017
CVSS 6.5
EPSS 0.00
CVE-2016-6335 HIGH
MediaWiki <1.23.15, <1.26.4, <1.27.1 - Info Disclosure
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-6334 MEDIUM
MediaWiki <1.23.15, <1.26.x-<1.26.4, <1.27.x-<1.27.1 - XSS
Apr 20, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6333 MEDIUM
MediaWiki <1.23.15, <1.26.x-<1.26.4, <1.27.x-<1.27.1 - XSS
Apr 20, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6332 HIGH
MediaWiki <1.23.15, <1.26.4, <1.27.1 - Info Disclosure
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-6331 HIGH
MediaWiki <1.23.15, <1.26.4, <1.27.1 - Auth Bypass
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2015-10058 LOW
Wikisource Category Browser < 2015-07-10 - Cross-Site Scripting via Lang Parameter
Jan 17, 2023
CVSS 3.5
EPSS 0.00
CVE-2015-8008 HIGH
MediaWiki < 1.25.3 - OAuth IP Address Access Restriction Bypass via API Request
Dec 29, 2017
CVSS 7.5
EPSS 0.01
CVE-2015-8009 CRITICAL
MediaWiki <1.25.3-1.24.4-1.23.11 - Auth Bypass
Jul 25, 2017
CVSS 9.8
EPSS 0.00
CVE-2015-8628 MEDIUM
MediaWiki < 1.23.12, 1.24.x < 1.24.5, 1.25.x < 1.25.4, 1.26.x < 1.26.1 - Sensitive User Login Info Exposure
Mar 23, 2017
CVSS 5.3
EPSS 0.00
CVE-2015-8627 MEDIUM
MediaWiki < 1.23.12, 1.24.x < 1.24.5, 1.25.x < 1.25.4, 1.26.x < 1.26.1 - Zero-Padded IP Address Bypass
Mar 23, 2017
CVSS 5.3
EPSS 0.00
CVE-2015-8626 CRITICAL
MediaWiki Weak Password Generation in User::randomPassword
Mar 23, 2017
CVSS 9.8
EPSS 0.01
CVE-2015-8625 HIGH
MediaWiki < 1.23.12, 1.24.x < 1.24.5, 1.25.x < 1.25.4, 1.26.x < 1.26.1 - Arbitrary File Read
Mar 23, 2017
CVSS 7.5
EPSS 0.00