mediawiki
431 tracked vulnerabilities.
CVE-2024-40598
MEDIUM
MediaWiki <1.42.1 - Info Disclosure
Jul 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-40597
HIGH
MediaWiki <1.42.1 - Info Disclosure
Jul 07, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-40596
MEDIUM
MediaWiki <1.42.1 - Info Disclosure
Jul 07, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-34507
HIGH
MediaWiki <1.39.7, <1.40.3, <1.41.1 - XSS
May 05, 2024
CVSS 7.4
EPSS 0.00
CVE-2024-34506
HIGH
MediaWiki <1.39.7, 1.40.x <1.40.3, 1.41.x <1.41.1 - DoS
May 05, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-34502
CRITICAL
MediaWiki <1.39.6-1.41.1 - Info Disclosure
May 05, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-34500
MEDIUM
MediaWiki <1.39.6, <1.40.2, <1.41.1 - XSS
May 05, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23179
MEDIUM
MediaWiki < 1.40.2 - Cross-Site Scripting via GlobalBlocking Extension Subtitle Links
Jan 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23178
MEDIUM
MediaWiki < 1.40.2 - Stored Cross-Site Scripting via Phonos Extension i18n Message
Jan 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-23177
MEDIUM
MediaWiki < 1.40.2 - Cross-Site Scripting via Special:PageStatistics Page Parameter
Jan 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23174
MEDIUM
MediaWiki PageTriage Extension < 1.35.14, 1.36-1.39 < 1.39.6, 1.40 < 1.40.2 - Stored XSS via Messages
Jan 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-23173
MEDIUM
MediaWiki Cargo XSS via Special:Drilldown Parameters
Jan 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-23172
MEDIUM
MediaWiki CheckUser Extension XSS via Message Definitions
Jan 12, 2024
CVSS 5.4
EPSS 0.01
CVE-2024-23171
MEDIUM
MediaWiki < 1.35.14, 1.36.x-1.39.x < 1.39.6, 1.40.x < 1.40.2 - Cross-Site Scripting via i18n Language Parameter
Jan 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2023-51704
MEDIUM
MediaWiki <1.35.14, <1.36-1.39.6, <1.40.2 - XSS
Dec 22, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-45362
MEDIUM
MediaWiki < 1.35.12, 1.36.x-1.39.x < 1.39.5, 1.40.x < 1.40.1 - Information Disclosure via diff-multi-sameuser
Nov 03, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-45360
MEDIUM
MediaWiki < 1.35.12, 1.36-1.39 < 1.39.5, 1.40 < 1.40.1 - Cross-Site Scripting in i18n Messages
Nov 03, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-45374
MEDIUM
MediaWiki SportsTeams Extension CSRF in Special Pages
Oct 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-45373
MEDIUM
MediaWiki ProofreadPage Extension XSS via formatNumNoSeparators
Oct 09, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-45372
MEDIUM
Wikibase extension <1.35.12, 1.36-1.39.5, 1.40-1.40.1 - Info Disclo...
Oct 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-45371
HIGH
MediaWiki Wikibase Extension Resource Allocation Flaw
Oct 09, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-45370
MEDIUM
MediaWiki SportsTeams Extension <1.35.12, 1.36.x-1.39.x <1.39.5, 1.40.x <1.40.1 - Missing Authorization
Oct 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-45369
MEDIUM
MediaWiki PageTriage < 1.35.12, 1.36-1.39 < 1.39.5, 1.40 < 1.40.1 - Unprotected User Data Exposure
Oct 09, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-45367
MEDIUM
MediaWiki CheckUser Extension DoS via cu_useragent_clienthints Table Flooding
Oct 09, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-45364
MEDIUM
MediaWiki 1.36.0-1.39.4 and 1.40.0 - Information Disclosure via Deleted Revision Permission Check
Oct 09, 2023
CVSS 5.3
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters