mediawiki

431 tracked vulnerabilities.

CVE-2021-42044 MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting in GrowthExperiments Mentor Dashboard Messages
Oct 06, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-42043 MEDIUM
MediaWiki < 1.36.2 - Cross-Site Scripting via Special:MediaSearch intitle: Operator
Oct 06, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-42042 MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting in GrowthExperiments Extension
Oct 06, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-42041 MEDIUM
MediaWiki < 1.36.2 - Stored Cross-Site Scripting via CentralAuth Rightsnone Message
Oct 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-42040 HIGH
MediaWiki < 1.36.2 - Denial of Service via Loops Extension Infinite Loop
Oct 06, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-31556 CRITICAL
MediaWiki <1.35.2 - Info Disclosure
Aug 12, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-36132 HIGH
MediaWiki < 1.36 - Incorrect Authorization in FileImporter Extension
Jul 02, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-36131 MEDIUM
MediaWiki < 1.36 - Authenticated Stored Cross-Site Scripting in SportsTeams Extension
Jul 02, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-36130 MEDIUM
MediaWiki < 1.36 - Authenticated Stored Cross-Site Scripting in SocialProfile Gift Data Fields
Jul 02, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-36129 MEDIUM
MediaWiki <1.36 - Privilege Escalation
Jul 02, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-36128 CRITICAL
MediaWiki < 1.36 - Improper Handling of Exceptional Conditions in CentralAuth Autoblocks
Jul 02, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-36127 MEDIUM
MediaWiki < 1.36 - Insecure Storage of Sensitive Information via Special:GlobalUserRights
Jul 02, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-36126 CRITICAL
MediaWiki < 1.36 - Denial of Service via AbuseFilter Block Message Fallback
Jul 02, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-36125 HIGH
MediaWiki < 1.36 - Denial of Service via Special:GlobalRenameRequest Infinite Loop
Jul 02, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-35197 HIGH
MediaWiki < 1.31.15, 1.32.x-1.35.x < 1.35.3, 1.36.x < 1.36.1 - Incorrect Authorization via Purge API
Jul 02, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-31555 HIGH
MediaWiki < 1.35.2 - Improper Input Validation in Oauth Extension
Apr 22, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-31554 MEDIUM
MediaWiki < 1.35.2 - Incorrect Authorization in AbuseFilter Extension
Apr 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-31553 MEDIUM
MediaWiki < 1.35.2 - Denial of Service via CheckUser Extension Username Handling
Apr 22, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-31552 MEDIUM
MediaWiki < 1.35.2 - Incorrect Authorization in AbuseFilter Account Creation Rules
Apr 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-31551 MEDIUM
MediaWiki < 1.35.2 - Cross-Site Scripting via PageForms Token Query Parameters
Apr 22, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-31550 MEDIUM
MediaWiki CommentBox extension < 1.35.2 - Cross-Site Scripting via Crafted Configuration Variables
Apr 22, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-31549 MEDIUM
MediaWiki < 1.35.2 - Exposure of Suppressed Usernames via AbuseFilter Examine Form
Apr 22, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-31548 MEDIUM
MediaWiki < 1.35.2 - Incorrect Authorization in AbuseFilter Extension
Apr 22, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-31547 MEDIUM
MediaWiki < 1.35.2 - Exposure of Sensitive Information via AbuseFilterCheckMatch API
Apr 22, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-31546 MEDIUM
MediaWiki < 1.35.2 - Sensitive Information Disclosure in AbuseFilter Log
Apr 22, 2021
CVSS 4.3
EPSS 0.00