mediawiki

431 tracked vulnerabilities.

CVE-2024-40598 MEDIUM
MediaWiki <1.42.1 - Info Disclosure
Jul 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-40597 HIGH
MediaWiki <1.42.1 - Info Disclosure
Jul 07, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-40596 MEDIUM
MediaWiki <1.42.1 - Info Disclosure
Jul 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-34507 HIGH
MediaWiki <1.39.7, <1.40.3, <1.41.1 - XSS
May 05, 2024
CVSS 7.4
EPSS 0.00
CVE-2024-34506 HIGH
MediaWiki <1.39.7, 1.40.x <1.40.3, 1.41.x <1.41.1 - DoS
May 05, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-34502 CRITICAL
MediaWiki <1.39.6-1.41.1 - Info Disclosure
May 05, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-34500 MEDIUM
MediaWiki <1.39.6, <1.40.2, <1.41.1 - XSS
May 05, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23179 MEDIUM
MediaWiki < 1.40.2 - Cross-Site Scripting via GlobalBlocking Extension Subtitle Links
Jan 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23178 MEDIUM
MediaWiki < 1.40.2 - Stored Cross-Site Scripting via Phonos Extension i18n Message
Jan 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-23177 MEDIUM
MediaWiki < 1.40.2 - Cross-Site Scripting via Special:PageStatistics Page Parameter
Jan 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23174 MEDIUM
MediaWiki PageTriage Extension < 1.35.14, 1.36-1.39 < 1.39.6, 1.40 < 1.40.2 - Stored XSS via Messages
Jan 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-23173 MEDIUM
MediaWiki Cargo XSS via Special:Drilldown Parameters
Jan 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23172 MEDIUM
MediaWiki CheckUser Extension XSS via Message Definitions
Jan 12, 2024
CVSS 5.4
EPSS 0.01
CVE-2024-23171 MEDIUM
MediaWiki < 1.35.14, 1.36.x-1.39.x < 1.39.6, 1.40.x < 1.40.2 - Cross-Site Scripting via i18n Language Parameter
Jan 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-51704 MEDIUM
MediaWiki <1.35.14, <1.36-1.39.6, <1.40.2 - XSS
Dec 22, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-45362 MEDIUM
MediaWiki < 1.35.12, 1.36.x-1.39.x < 1.39.5, 1.40.x < 1.40.1 - Information Disclosure via diff-multi-sameuser
Nov 03, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-45360 MEDIUM
MediaWiki < 1.35.12, 1.36-1.39 < 1.39.5, 1.40 < 1.40.1 - Cross-Site Scripting in i18n Messages
Nov 03, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-45374 MEDIUM
MediaWiki SportsTeams Extension CSRF in Special Pages
Oct 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-45373 MEDIUM
MediaWiki ProofreadPage Extension XSS via formatNumNoSeparators
Oct 09, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-45372 MEDIUM
Wikibase extension <1.35.12, 1.36-1.39.5, 1.40-1.40.1 - Info Disclo...
Oct 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-45371 HIGH
MediaWiki Wikibase Extension Resource Allocation Flaw
Oct 09, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-45370 MEDIUM
MediaWiki SportsTeams Extension <1.35.12, 1.36.x-1.39.x <1.39.5, 1.40.x <1.40.1 - Missing Authorization
Oct 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-45369 MEDIUM
MediaWiki PageTriage < 1.35.12, 1.36-1.39 < 1.39.5, 1.40 < 1.40.1 - Unprotected User Data Exposure
Oct 09, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-45367 MEDIUM
MediaWiki CheckUser Extension DoS via cu_useragent_clienthints Table Flooding
Oct 09, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-45364 MEDIUM
MediaWiki 1.36.0-1.39.4 and 1.40.0 - Information Disclosure via Deleted Revision Permission Check
Oct 09, 2023
CVSS 5.3
EPSS 0.00