mediawiki
431 tracked vulnerabilities.
CVE-2022-39193
MEDIUM
MediaWiki CheckUser Extension - Unauthorized Exposure of Sensitive Edit and Action Performer Information
Jan 20, 2023
CVSS 5.3
EPSS 0.00
CVE-2022-47927
MEDIUM
MediaWiki Credential Exposure via SQLite File Permissions
Jan 12, 2023
CVSS 5.5
EPSS 0.00
CVE-2022-41767
MEDIUM
MediaWiki <1.35.8, 1.36.x, 1.37.x <1.37.5, 1.38.x <1.38.3 - Info Di...
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-41765
MEDIUM
MediaWiki <1.35.8-1.38.3 - Info Disclosure
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-4561
LOW
SemanticDrilldown < 2022-08-12 - Cross-Site Scripting via GET Parameter Handler
Dec 16, 2022
CVSS 3.5
EPSS 0.00
CVE-2022-28204
HIGH
MediaWiki 1.37.0-1.37.1 - Denial of Service via Special:WhatLinksHere Endpoint
Sep 19, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-28203
HIGH
MediaWiki < 1.35.6, 1.36.x < 1.36.4, 1.37.x < 1.37.2 - Denial of Service via Special:NewFiles Query
Sep 19, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-28201
MEDIUM
MediaWiki <1.35.6-1.37.2 - Info Disclosure
Sep 19, 2022
CVSS 4.4
EPSS 0.00
CVE-2022-39194
MEDIUM
MediaWiki < 1.38.2 - Denial of Service via GrowthExperiments Community Configuration
Sep 02, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-34912
MEDIUM
MediaWiki < 1.37.3 and 1.38.x < 1.38.1 - Cross-Site Scripting in Special:Contributions Page Title
Jul 02, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-34911
MEDIUM
MediaWiki < 1.35.7, 1.36.x-1.37.x < 1.37.3, 1.38.x < 1.38.1 - Cross-Site Scripting via Username in Account Creation
Jul 02, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-34750
HIGH
MediaWiki < 1.38.1 - Denial of Service via Unvalidated Lemma Length in Wikibase Lexeme
Jun 28, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-29969
MEDIUM
RSS for MediaWiki < 2022-04-29 - Cross-Site Scripting via RSS Element
May 02, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-28323
HIGH
MediaWiki <1.37.2 - Info Disclosure
Apr 30, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-29907
MEDIUM
MediaWiki < 1.37.2 - Cross-Site Scripting in Nimbus Skin Advertise Link Messages
Apr 29, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-29906
CRITICAL
MediaWiki QuizGame Extension < 1.37.2 - Missing Authorization in Admin API Module
Apr 29, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-29905
MEDIUM
MediaWiki FanBoxes < 1.37.2 - Cross-Site Request Forgery via Special:UserBoxes
Apr 29, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-29904
CRITICAL
MediaWiki SemanticDrilldown < 1.37.2 - SQL Injection via Constraint Handling
Apr 29, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-29903
MEDIUM
MediaWiki Private Domains Extension < 1.37.2 - Cross-Site Request Forgery via Special:PrivateDomains
Apr 29, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-29547
HIGH
CreateRedirect < 2022-04-14 - Unauthenticated Page Edit via Permission Bypass
Apr 21, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-28209
CRITICAL
Mediawiki <1.37.1 - Info Disclosure
Mar 30, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-28206
CRITICAL
MediaWiki <1.37.1 - Info Disclosure
Mar 30, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-28205
CRITICAL
MediaWiki <1.37.1 - Info Disclosure
Mar 30, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-28202
MEDIUM
MediaWiki < 1.35.6, 1.36.x < 1.36.4, 1.37.x < 1.37.2 - Cross-Site Scripting via Gallery and Special:RevisionDelete
Mar 30, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-21710
MEDIUM
ShortDescription < 2.3.4 - Cross-Site Scripting via SHORTDESC Wikitext
Jan 24, 2022
CVSS 4.7
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters