mediawiki
431 tracked vulnerabilities.
CVE-2021-42044
MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting in GrowthExperiments Mentor Dashboard Messages
Oct 06, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-42043
MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting via Special:MediaSearch intitle: Operator
Oct 06, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-42042
MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting in GrowthExperiments Extension
Oct 06, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-42041
MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting via CentralAuth Rightsnone Message
Oct 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-42040
HIGH
MediaWiki < 1.36.2 - Denial of Service via Loops Extension Infinite Loop
Oct 06, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-31556
CRITICAL
MediaWiki <1.35.2 - Info Disclosure
Aug 12, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-36132
HIGH
MediaWiki < 1.36 - Incorrect Authorization in FileImporter Extension
Jul 02, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-36131
MEDIUM
MediaWiki < 1.36 - Authenticated Stored Cross-Site Scripting in SportsTeams Extension
Jul 02, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-36130
MEDIUM
MediaWiki < 1.36 - Authenticated Stored Cross-Site Scripting in SocialProfile Gift Data Fields
Jul 02, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-36129
MEDIUM
MediaWiki <1.36 - Privilege Escalation
Jul 02, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-36128
CRITICAL
MediaWiki < 1.36 - Improper Handling of Exceptional Conditions in CentralAuth Autoblocks
Jul 02, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-36127
MEDIUM
MediaWiki < 1.36 - Insecure Storage of Sensitive Information via Special:GlobalUserRights
Jul 02, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-36126
CRITICAL
MediaWiki < 1.36 - Denial of Service via AbuseFilter Block Message Fallback
Jul 02, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-36125
HIGH
MediaWiki < 1.36 - Denial of Service via Special:GlobalRenameRequest Infinite Loop
Jul 02, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-35197
HIGH
MediaWiki < 1.31.15, 1.32.x-1.35.x < 1.35.3, 1.36.x < 1.36.1 - Incorrect Authorization via Purge API
Jul 02, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-31555
HIGH
MediaWiki < 1.35.2 - Improper Input Validation in Oauth Extension
Apr 22, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-31554
MEDIUM
MediaWiki < 1.35.2 - Incorrect Authorization in AbuseFilter Extension
Apr 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-31553
MEDIUM
MediaWiki < 1.35.2 - Denial of Service via CheckUser Extension Username Handling
Apr 22, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-31552
MEDIUM
MediaWiki < 1.35.2 - Incorrect Authorization in AbuseFilter Account Creation Rules
Apr 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-31551
MEDIUM
MediaWiki < 1.35.2 - Cross-Site Scripting via PageForms Token Query Parameters
Apr 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-31550
MEDIUM
MediaWiki CommentBox extension < 1.35.2 - Cross-Site Scripting via Crafted Configuration Variables
Apr 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-31549
MEDIUM
MediaWiki < 1.35.2 - Exposure of Suppressed Usernames via AbuseFilter Examine Form
Apr 22, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-31548
MEDIUM
MediaWiki < 1.35.2 - Incorrect Authorization in AbuseFilter Extension
Apr 22, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-31547
MEDIUM
MediaWiki < 1.35.2 - Exposure of Sensitive Information via AbuseFilterCheckMatch API
Apr 22, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-31546
MEDIUM
MediaWiki < 1.35.2 - Sensitive Information Disclosure in AbuseFilter Log
Apr 22, 2021
CVSS 4.3
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters