mediawiki

431 tracked vulnerabilities.

CVE-2022-39193 MEDIUM
MediaWiki CheckUser Extension - Unauthorized Exposure of Sensitive Edit and Action Performer Information
Jan 20, 2023
CVSS 5.3
EPSS 0.00
CVE-2022-47927 MEDIUM
MediaWiki Credential Exposure via SQLite File Permissions
Jan 12, 2023
CVSS 5.5
EPSS 0.00
CVE-2022-41767 MEDIUM
MediaWiki <1.35.8, 1.36.x, 1.37.x <1.37.5, 1.38.x <1.38.3 - Info Di...
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-41765 MEDIUM
MediaWiki <1.35.8-1.38.3 - Info Disclosure
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-4561 LOW
SemanticDrilldown < 2022-08-12 - Cross-Site Scripting via GET Parameter Handler
Dec 16, 2022
CVSS 3.5
EPSS 0.00
CVE-2022-28204 HIGH
MediaWiki 1.37.0-1.37.1 - Denial of Service via Special:WhatLinksHere Endpoint
Sep 19, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-28203 HIGH
MediaWiki < 1.35.6, 1.36.x < 1.36.4, 1.37.x < 1.37.2 - Denial of Service via Special:NewFiles Query
Sep 19, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-28201 MEDIUM
MediaWiki <1.35.6-1.37.2 - Info Disclosure
Sep 19, 2022
CVSS 4.4
EPSS 0.00
CVE-2022-39194 MEDIUM
MediaWiki < 1.38.2 - Denial of Service via GrowthExperiments Community Configuration
Sep 02, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-34912 MEDIUM
MediaWiki < 1.37.3 and 1.38.x < 1.38.1 - Cross-Site Scripting in Special:Contributions Page Title
Jul 02, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-34911 MEDIUM
MediaWiki < 1.35.7, 1.36.x-1.37.x < 1.37.3, 1.38.x < 1.38.1 - Cross-Site Scripting via Username in Account Creation
Jul 02, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-34750 HIGH
MediaWiki < 1.38.1 - Denial of Service via Unvalidated Lemma Length in Wikibase Lexeme
Jun 28, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-29969 MEDIUM
RSS for MediaWiki < 2022-04-29 - Cross-Site Scripting via RSS Element
May 02, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-28323 HIGH
MediaWiki <1.37.2 - Info Disclosure
Apr 30, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-29907 MEDIUM
MediaWiki < 1.37.2 - Cross-Site Scripting in Nimbus Skin Advertise Link Messages
Apr 29, 2022
CVSS 6.1
EPSS 0.00
CVE-2022-29906 CRITICAL
MediaWiki QuizGame Extension < 1.37.2 - Missing Authorization in Admin API Module
Apr 29, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-29905 MEDIUM
MediaWiki FanBoxes < 1.37.2 - Cross-Site Request Forgery via Special:UserBoxes
Apr 29, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-29904 CRITICAL
MediaWiki SemanticDrilldown < 1.37.2 - SQL Injection via Constraint Handling
Apr 29, 2022
CVSS 9.8
EPSS 0.01
CVE-2022-29903 MEDIUM
MediaWiki Private Domains Extension < 1.37.2 - Cross-Site Request Forgery via Special:PrivateDomains
Apr 29, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-29547 HIGH
CreateRedirect < 2022-04-14 - Unauthenticated Page Edit via Permission Bypass
Apr 21, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-28209 CRITICAL
Mediawiki <1.37.1 - Info Disclosure
Mar 30, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-28206 CRITICAL
MediaWiki <1.37.1 - Info Disclosure
Mar 30, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-28205 CRITICAL
MediaWiki <1.37.1 - Info Disclosure
Mar 30, 2022
CVSS 9.8
EPSS 0.00
CVE-2022-28202 MEDIUM
MediaWiki < 1.35.6, 1.36.x < 1.36.4, 1.37.x < 1.37.2 - Cross-Site Scripting via Gallery and Special:RevisionDelete
Mar 30, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-21710 MEDIUM
ShortDescription < 2.3.4 - Cross-Site Scripting via SHORTDESC Wikitext
Jan 24, 2022
CVSS 4.7
EPSS 0.00