mediawiki

431 tracked vulnerabilities.

CVE-2025-61646 MEDIUM
MediaWiki <1.39.14-1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-61645 MEDIUM
MediaWiki < 1.44.1 - Cross-Site Scripting in CodexTablePager
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-11261 MEDIUM
MediaWiki < 1.39.15, 1.43.5, 1.44.2 - Cross-Site Scripting in mediawiki.Language.Js
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61643 MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61642 MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in HTMLForm Code
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61641 MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-61640 MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in RclToOrFromWidget
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61639 MEDIUM
MediaWiki <1.39.14-1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61638 MEDIUM
MediaWiki <1.39.14, 1.43.4, 1.44.1 - XSS
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61637 MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in Edit Preview
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61636 MEDIUM
MediaWiki < 1.39.14, 1.43.4, 1.44.1 - Cross-Site Scripting in HTMLButtonField
Feb 03, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-61634 LOW
MediaWiki <1.39.14, 1.43.4, 1.44.1 - Info Disclosure
Feb 03, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-62671 MEDIUM
MediaWiki Cargo Extension < 3.8.3 - Stored Cross-Site Scripting
Oct 18, 2025
EPSS 0.00
CVE-2025-23081 MEDIUM
MediaWiki DataTransfer Extension 1.39.0-1.39.10, 1.41.0-1.41.2, 1.42.0-1.42.1 - CSRF and XSS
Jan 14, 2025
CVSS 6.1
EPSS 0.00
CVE-2024-47849 CRITICAL
Mediawiki - Cargo <3.6.1 - SQL Injection
Oct 05, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-47847 MEDIUM
The Wikimedia Foundation Mediawiki - Cargo <3.6.1 - XSS
Oct 05, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-47846 HIGH
Mediawiki Cargo 3.6.X < 3.6.1 - Cross-Site Request Forgery
Oct 05, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-47913 MEDIUM
MediaWiki AbuseFilter <1.39.9, 1.40.x-1.41.x<1.41.3, 1.42.x<1.42.2 - API Unauthorized Log Disclosure
Oct 04, 2024
CVSS 5.3
EPSS 0.01
CVE-2024-40605 MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting via Foreground Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40604 MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting via Nimbus Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40603 MEDIUM
MediaWiki < 1.42.1 - Cross-Site Request Forgery via Special:ChangeRating
Jul 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-40602 MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting in Tempo Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40601 MEDIUM
MediaWiki < 1.42.1 - Cross-Site Request Forgery in MediaWikiChat Extension API Modules
Jul 07, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-40600 MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting in Metrolook Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00
CVE-2024-40599 MEDIUM
MediaWiki < 1.42.1 - Stored Cross-Site Scripting in GuMaxDD Skin Sidebar Menu Entries
Jul 07, 2024
CVSS 4.8
EPSS 0.00