mediawiki

431 tracked vulnerabilities.

CVE-2021-30153 MEDIUM
MediaWiki <1.35.2 - Info Disclosure
Apr 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2021-44856 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - AbuseFilter Bypass via Special:ChangeContentModel
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-44855 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Stored Cross-Site Scripting via Upload Image URL
Dec 26, 2022
CVSS 5.4
EPSS 0.01
CVE-2021-44854 MEDIUM
MediaWiki <1.35.5-1.37.1 - Info Disclosure
Dec 26, 2022
CVSS 5.3
EPSS 0.00
CVE-2021-42049 MEDIUM
MediaWiki <1.36.2 - Info Disclosure
Sep 29, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-42048 MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting via Growth Extension Newcomer Home Page Footer
Sep 29, 2022
CVSS 4.8
EPSS 0.00
CVE-2021-42047 MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting via Mentor Dashboard Mentee Overview
Sep 29, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-42046 MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting in GlobalWatchlist Extension Messages
Sep 29, 2022
CVSS 6.1
EPSS 0.00
CVE-2021-42045 MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting via SecurePoll User-Agent Header
Sep 29, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-46150 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Cross-Site Scripting via Special:CheckUserLog Date Handling
Jan 10, 2022
CVSS 4.8
EPSS 0.00
CVE-2021-46149 HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Denial of Service via Language Name Search
Jan 10, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-46148 MEDIUM
MediaWiki <1.35.5-1.37.1 - Info Disclosure
Jan 10, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-46147 HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Cross-Site Request Forgery
Jan 10, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-46146 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Cross-Site Scripting in WikibaseMediaInfo Caption Fields
Jan 10, 2022
CVSS 5.4
EPSS 0.00
CVE-2021-45474 MEDIUM
MediaWiki < 1.37 - Cross-Site Scripting via Special:ImportFile clientUrl Parameter
Dec 24, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-45473 MEDIUM
MediaWiki <= 1.37 - Stored Cross-Site Scripting via Wikibase Item Descriptions
Dec 24, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-45472 MEDIUM
MediaWiki <= 1.37 - Cross-Site Scripting via Wikibase External Identifier URL Format
Dec 24, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-45471 MEDIUM
MediaWiki <= 1.37 - Authenticated Bypass of IP Block via EntitySchema Edit
Dec 24, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-44858 HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Unauthenticated Private Page Access via Undo and Restore Actions
Dec 20, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-45038 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Private Wiki Contents Exposure via Rollback
Dec 17, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-44857 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Arbitrary Page Content Replacement via mcrrestore
Dec 17, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-41801 HIGH
MediaWiki ReplaceText extension through 1.41 - Incorrect Access Control
Oct 11, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-41800 MEDIUM
MediaWiki < 1.36.2 - Denial of Service via Special:Contributions PoolCounter Mishandling
Oct 11, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-41799 HIGH
MediaWiki < 1.36.2 - Denial of Service via ApiQueryBacklinks
Oct 11, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-41798 MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting via Month-Related Messages on Special:Search
Oct 11, 2021
CVSS 6.1
EPSS 0.00