mediawiki
431 tracked vulnerabilities.
CVE-2021-30153
MEDIUM
MediaWiki <1.35.2 - Info Disclosure
Apr 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2021-44856
MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - AbuseFilter Bypass via Special:ChangeContentModel
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-44855
MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Stored Cross-Site Scripting via Upload Image URL
Dec 26, 2022
CVSS 5.4
EPSS 0.01
CVE-2021-44854
MEDIUM
MediaWiki <1.35.5-1.37.1 - Info Disclosure
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-42049
MEDIUM
MediaWiki <1.36.2 - Info Disclosure
Sep 29, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-42048
MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting via Growth Extension Newcomer Home Page Footer
Sep 29, 2022
CVSS 4.8
EPSS 0.00
CVE-2021-42047
MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting via Mentor Dashboard Mentee Overview
Sep 29, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-42046
MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting in GlobalWatchlist Extension Messages
Sep 29, 2022
CVSS 6.1
EPSS 0.00
CVE-2021-42045
MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting via SecurePoll User-Agent Header
Sep 29, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-46150
MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Cross-Site Scripting via Special:CheckUserLog Date Handling
Jan 10, 2022
CVSS 4.8
EPSS 0.00
CVE-2021-46149
HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Denial of Service via Language Name Search
Jan 10, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-46148
MEDIUM
MediaWiki <1.35.5-1.37.1 - Info Disclosure
Jan 10, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-46147
HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Cross-Site Request Forgery
Jan 10, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-46146
MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Cross-Site Scripting in WikibaseMediaInfo Caption Fields
Jan 10, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-45474
MEDIUM
MediaWiki < 1.37 - Cross-Site Scripting via Special:ImportFile clientUrl Parameter
Dec 24, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-45473
MEDIUM
MediaWiki <= 1.37 - Stored Cross-Site Scripting via Wikibase Item Descriptions
Dec 24, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-45472
MEDIUM
MediaWiki <= 1.37 - Cross-Site Scripting via Wikibase External Identifier URL Format
Dec 24, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-45471
MEDIUM
MediaWiki <= 1.37 - Authenticated Bypass of IP Block via EntitySchema Edit
Dec 24, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-44858
HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Unauthenticated Private Page Access via Undo and Restore Actions
Dec 20, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-45038
MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Private Wiki Contents Exposure via Rollback
Dec 17, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-44857
MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Arbitrary Page Content Replacement via mcrrestore
Dec 17, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-41801
HIGH
MediaWiki ReplaceText extension through 1.41 - Incorrect Access Control
Oct 11, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-41800
MEDIUM
MediaWiki < 1.36.2 - Denial of Service via Special:Contributions PoolCounter Mishandling
Oct 11, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-41799
HIGH
MediaWiki < 1.36.2 - Denial of Service via ApiQueryBacklinks
Oct 11, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-41798
MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting via Month-Related Messages on Special:Search
Oct 11, 2021
CVSS 6.1
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters