mediawiki
431 tracked vulnerabilities.
CVE-2017-0364
MEDIUM
MediaWiki < 1.23.16 - URL Redirection to Untrusted Site via Special:Search
Apr 13, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-0363
MEDIUM
MediaWiki < 1.23.16 - URL Redirection to Untrusted Site via Special:UserLogin returnto Parameter
Apr 13, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-0362
HIGH
MediaWiki < 1.23.16 - Cross-Site Request Forgery via Watchlist Mark All Pages Visited
Apr 13, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-0361
HIGH
MediaWiki < 1.23.16 - Exposure of Sensitive Information via API Log
Apr 13, 2018
CVSS 7.8
EPSS 0.00
CVE-2017-8815
HIGH
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Attribute Injection via Language Converter Glossary Rules
Nov 15, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-8814
HIGH
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Text Injection via Language Converter Rule Definition
Nov 15, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-8812
MEDIUM
MediaWiki <1.27.4, <1.28.3, <1.29.2 - XSS
Nov 15, 2017
CVSS 5.3
EPSS 0.01
CVE-2017-8811
MEDIUM
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - HTML Mangling via Raw Message Parameter Expansion
Nov 15, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-8810
HIGH
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Username Enumeration via Login Error Messages
Nov 15, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-8809
CRITICAL
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Reflected File Download via api.php
Nov 15, 2017
CVSS 9.8
EPSS 0.18
CVE-2017-8808
MEDIUM
MediaWiki < 1.27.4, 1.28.x < 1.28.3, 1.29.x < 1.29.2 - Cross-Site Scripting via Non-Standard URL Escaping
Nov 15, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6337
HIGH
MediaWiki 1.27.x - Improper Access Control via UserGetRights Function
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-6336
MEDIUM
MediaWiki <1.23.15, <1.26.x-1.26.4, <1.27.x-1.27.1 - Auth Bypass
Apr 20, 2017
CVSS 6.5
EPSS 0.00
CVE-2016-6335
HIGH
MediaWiki <1.23.15, <1.26.4, <1.27.1 - Info Disclosure
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-6334
MEDIUM
MediaWiki <1.23.15, <1.26.x-<1.26.4, <1.27.x-<1.27.1 - XSS
Apr 20, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6333
MEDIUM
MediaWiki <1.23.15, <1.26.x-<1.26.4, <1.27.x-<1.27.1 - XSS
Apr 20, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-6332
HIGH
MediaWiki <1.23.15, <1.26.4, <1.27.1 - Info Disclosure
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-6331
HIGH
MediaWiki <1.23.15, <1.26.4, <1.27.1 - Auth Bypass
Apr 20, 2017
CVSS 7.5
EPSS 0.00
CVE-2015-10058
LOW
Wikisource Category Browser < 2015-07-10 - Cross-Site Scripting via Lang Parameter
Jan 17, 2023
CVSS 3.5
EPSS 0.00
CVE-2015-8008
HIGH
MediaWiki < 1.25.3 - OAuth IP Address Access Restriction Bypass via API Request
Dec 29, 2017
CVSS 7.5
EPSS 0.01
CVE-2015-8009
CRITICAL
MediaWiki <1.25.3-1.24.4-1.23.11 - Auth Bypass
Jul 25, 2017
CVSS 9.8
EPSS 0.00
CVE-2015-8628
MEDIUM
MediaWiki < 1.23.12, 1.24.x < 1.24.5, 1.25.x < 1.25.4, 1.26.x < 1.26.1 - Sensitive User Login Info Exposure
Mar 23, 2017
CVSS 5.3
EPSS 0.00
CVE-2015-8627
MEDIUM
MediaWiki < 1.23.12, 1.24.x < 1.24.5, 1.25.x < 1.25.4, 1.26.x < 1.26.1 - Zero-Padded IP Address Bypass
Mar 23, 2017
CVSS 5.3
EPSS 0.00
CVE-2015-8626
CRITICAL
MediaWiki Weak Password Generation in User::randomPassword
Mar 23, 2017
CVSS 9.8
EPSS 0.01
CVE-2015-8625
HIGH
MediaWiki < 1.23.12, 1.24.x < 1.24.5, 1.25.x < 1.25.4, 1.26.x < 1.26.1 - Arbitrary File Read
Mar 23, 2017
CVSS 7.5
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters