mediawiki
431 tracked vulnerabilities.
CVE-2023-45363
HIGH
MediaWiki < 1.35.12, 1.36.x-1.39.x < 1.39.5, 1.40.x < 1.40.1 - Denial of Service via Redirect and ConvertTitles Query
Oct 09, 2023
CVSS 7.5
EPSS 0.11
CVE-2023-3550
HIGH
Mediawiki v1.40.0 - Privilege Escalation
Sep 25, 2023
CVSS 7.3
EPSS 0.00
CVE-2023-36674
MEDIUM
MediaWiki <1.35.11, <1.38.7, <1.39.4, <1.40.1 - Auth Bypass
Aug 20, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37305
MEDIUM
MediaWiki ProofreadPage Extension < 1.39.3 - Hidden User Data Exposure via Public Interfaces
Jun 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37304
MEDIUM
MediaWiki < 1.39.3 - Cross-Site Scripting via DoubleWiki Column Alignment Feature
Jun 30, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-37303
CRITICAL
MediaWiki < 1.39.3 - Denial of Service via CheckUser Extension Block Attempt
Jun 30, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-37302
MEDIUM
MediaWiki < 1.39.3 - Cross-Site Scripting via SiteLinksView Badge Title Attribute
Jun 30, 2023
CVSS 6.1
EPSS 0.02
CVE-2023-37301
MEDIUM
MediaWiki < 1.39.3 - AbuseFilter Bypass via SubmitEntityAction
Jun 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37300
MEDIUM
MediaWiki < 1.39.3 - Incorrect Authorization in CheckUserLog API
Jun 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37256
MEDIUM
MediaWiki Cargo Extension < 1.39.3 - Stored Cross-Site Scripting via javascript: URL
Jun 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-37255
MEDIUM
MediaWiki < 1.39.3 - Cross-Site Scripting via User-Agent HTTP Header
Jun 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-37254
MEDIUM
MediaWiki Cargo Extension < 1.39.3 - Cross-Site Scripting via Special:CargoQuery
Jun 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-37251
MEDIUM
MediaWiki < 1.39.3 - Stored Cross-Site Scripting via GoogleAnalyticsMetrics Extension
Jun 29, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-36675
MEDIUM
MediaWiki <1.35.11, <1.36-1.38.7, <1.39.4 - XSS
Jun 26, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-29141
CRITICAL
MediaWiki <1.35.10, <1.36, <1.38.6, <1.39.3 - Info Disclosure
Mar 31, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-29140
MEDIUM
MediaWiki <1.39.3 - Info Disclosure
Mar 31, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-29139
MEDIUM
MediaWiki < 1.39.3 - Denial of Service via CheckUserLog API Request Flood
Mar 31, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-29137
MEDIUM
MediaWiki <1.39.3 - Info Disclosure
Mar 31, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-22912
MEDIUM
MediaWiki <1.35.9, <1.38.5, <1.39.1 - Info Disclosure
Jan 20, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-22910
MEDIUM
MediaWiki < 1.35.9, 1.36.x-1.38.x < 1.38.5, 1.39.x < 1.39.1 - Cross-Site Scripting via Wikibase Date Formatting
Jan 20, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-22945
MEDIUM
MediaWiki GrowthExperiments < 1.39.0 - Incorrect Authorization in Mentor List Management
Jan 11, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-22911
MEDIUM
MediaWiki < 1.35.9, 1.36.x-1.38.x < 1.38.5, 1.39.x < 1.39.1 - XSS via E-Widgets HTML Attribute
Jan 10, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-22909
MEDIUM
MediaWiki < 1.35.9, 1.36.x-1.38.x < 1.38.5, 1.39.x < 1.39.1 - Denial of Service via SpecialMobileHistory
Jan 10, 2023
CVSS 5.3
EPSS 0.01
CVE-2022-48614
MEDIUM
Semantic MediaWiki < 4.0.2 - Reflected Cross-Site Scripting via Special:Ask
Dec 10, 2023
CVSS 6.1
EPSS 0.00
CVE-2022-41766
MEDIUM
MediaWiki <1.35.8-1.37.5-1.38.3 - Info Disclosure
May 29, 2023
CVSS 4.3
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters