mediawiki

431 tracked vulnerabilities.

CVE-2023-45363 HIGH
MediaWiki < 1.35.12, 1.36.x-1.39.x < 1.39.5, 1.40.x < 1.40.1 - Denial of Service via Redirect and ConvertTitles Query
Oct 09, 2023
CVSS 7.5
EPSS 0.11
CVE-2023-3550 HIGH
Mediawiki v1.40.0 - Privilege Escalation
Sep 25, 2023
CVSS 7.3
EPSS 0.00
CVE-2023-36674 MEDIUM
MediaWiki <1.35.11, <1.38.7, <1.39.4, <1.40.1 - Auth Bypass
Aug 20, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37305 MEDIUM
MediaWiki ProofreadPage Extension < 1.39.3 - Hidden User Data Exposure via Public Interfaces
Jun 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37304 MEDIUM
MediaWiki < 1.39.3 - Cross-Site Scripting via DoubleWiki Column Alignment Feature
Jun 30, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-37303 CRITICAL
MediaWiki < 1.39.3 - Denial of Service via CheckUser Extension Block Attempt
Jun 30, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-37302 MEDIUM
MediaWiki < 1.39.3 - Cross-Site Scripting via SiteLinksView Badge Title Attribute
Jun 30, 2023
CVSS 6.1
EPSS 0.02
CVE-2023-37301 MEDIUM
MediaWiki < 1.39.3 - AbuseFilter Bypass via SubmitEntityAction
Jun 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37300 MEDIUM
MediaWiki < 1.39.3 - Incorrect Authorization in CheckUserLog API
Jun 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-37256 MEDIUM
MediaWiki Cargo Extension < 1.39.3 - Stored Cross-Site Scripting via javascript: URL
Jun 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-37255 MEDIUM
MediaWiki < 1.39.3 - Cross-Site Scripting via User-Agent HTTP Header
Jun 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-37254 MEDIUM
MediaWiki Cargo Extension < 1.39.3 - Cross-Site Scripting via Special:CargoQuery
Jun 29, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-37251 MEDIUM
MediaWiki < 1.39.3 - Stored Cross-Site Scripting via GoogleAnalyticsMetrics Extension
Jun 29, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-36675 MEDIUM
MediaWiki <1.35.11, <1.36-1.38.7, <1.39.4 - XSS
Jun 26, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-29141 CRITICAL
MediaWiki <1.35.10, <1.36, <1.38.6, <1.39.3 - Info Disclosure
Mar 31, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-29140 MEDIUM
MediaWiki <1.39.3 - Info Disclosure
Mar 31, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-29139 MEDIUM
MediaWiki < 1.39.3 - Denial of Service via CheckUserLog API Request Flood
Mar 31, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-29137 MEDIUM
MediaWiki <1.39.3 - Info Disclosure
Mar 31, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-22912 MEDIUM
MediaWiki <1.35.9, <1.38.5, <1.39.1 - Info Disclosure
Jan 20, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-22910 MEDIUM
MediaWiki < 1.35.9, 1.36.x-1.38.x < 1.38.5, 1.39.x < 1.39.1 - Cross-Site Scripting via Wikibase Date Formatting
Jan 20, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-22945 MEDIUM
MediaWiki GrowthExperiments < 1.39.0 - Incorrect Authorization in Mentor List Management
Jan 11, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-22911 MEDIUM
MediaWiki < 1.35.9, 1.36.x-1.38.x < 1.38.5, 1.39.x < 1.39.1 - XSS via E-Widgets HTML Attribute
Jan 10, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-22909 MEDIUM
MediaWiki < 1.35.9, 1.36.x-1.38.x < 1.38.5, 1.39.x < 1.39.1 - Denial of Service via SpecialMobileHistory
Jan 10, 2023
CVSS 5.3
EPSS 0.01
CVE-2022-48614 MEDIUM
Semantic MediaWiki < 4.0.2 - Reflected Cross-Site Scripting via Special:Ask
Dec 10, 2023
CVSS 6.1
EPSS 0.00
CVE-2022-41766 MEDIUM
MediaWiki <1.35.8-1.37.5-1.38.3 - Info Disclosure
May 29, 2023
CVSS 4.3
EPSS 0.00