mediawiki

431 tracked vulnerabilities.

CVE-2021-31545 MEDIUM
MediaWiki < 1.35.2 - Exposure of Deleted Usernames via AbuseFilter page_recent_contributors
Apr 22, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-30159 MEDIUM
MediaWiki < 1.31.12 and 1.32.x-1.35.x < 1.35.2 - Unintended Page Deletion via Fast Double Move
Apr 09, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-30156 MEDIUM
MediaWiki <1.35.2 - Info Disclosure
Apr 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-30155 MEDIUM
MediaWiki <1.35.2 - Privilege Escalation
Apr 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-30152 MEDIUM
MediaWiki <1.31.13, 1.32-1.35.1 - Privilege Escalation
Apr 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-30158 MEDIUM
MediaWiki <1.35.2 - Info Disclosure
Apr 06, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-30157 MEDIUM
MediaWiki < 1.31.12 and 1.32.x-1.35.x < 1.35.2 - Stored Cross-Site Scripting in ChangesList Filter Labels
Apr 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-30154 MEDIUM
MediaWiki < 1.31.12 and 1.32.x-1.35.x < 1.35.2 - Cross-Site Scripting via Special:NewFiles
Apr 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2020-29007 CRITICAL
MediaWiki Score < 0.3.0 - Remote Code Execution via GNU LilyPond Sandbox Escape
Apr 15, 2023
CVSS 9.8
EPSS 0.25
CVE-2020-29005 HIGH
MediaWiki < 1.35 - Cleartext Transmission of Sensitive Information in Push Extension API
Jan 29, 2021
CVSS 7.5
EPSS 0.00
CVE-2020-29004 HIGH
MediaWiki < 1.35 - Cross-Site Request Forgery via Push Extension API
Jan 29, 2021
CVSS 8.8
EPSS 0.00
CVE-2020-35626 HIGH
MediaWiki < 1.35.1 - Cross-Site Request Forgery in PushToWatch Extension
Dec 21, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-35625 HIGH
MediaWiki < 1.35.1 - Unauthenticated Arbitrary Static Function Execution via Widgets Extension HTML Comment
Dec 21, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-35624 MEDIUM
MediaWiki < 1.35.1 - Information Disclosure via SecurePoll Vote Timestamp
Dec 21, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-35623 HIGH
MediaWiki <1.35.1 - Privilege Escalation
Dec 21, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-35622 MEDIUM
MediaWiki GlobalUsage Extension < 1.35.1 - Cross-Site Scripting via Unsafe WikiMap Link Generation
Dec 21, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-35480 MEDIUM
MediaWiki < 1.35.1 - Information Disclosure of Hidden User Accounts
Dec 18, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-35479 MEDIUM
MediaWiki 1.12.0-1.35.0 - Cross-Site Scripting via BlockLogFormatter.php
Dec 18, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-35478 MEDIUM
MediaWiki 1.33.0-1.35.0 - Cross-Site Scripting via BlockLogFormatter.php
Dec 18, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-35477 MEDIUM
MediaWiki <1.35.1 - Info Disclosure
Dec 18, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-35475 HIGH
MediaWiki < 1.35.1 - Cross-Site Scripting in UserRights Special Page
Dec 18, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-35474 MEDIUM
MediaWiki < 1.35.1 - Stored Cross-Site Scripting via MediaWiki:recentchanges-legend-watchlistexpiry
Dec 18, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-29003 MEDIUM
MediaWiki PollNY extension < 1.35 - Stored Cross-Site Scripting via Poll Answer Option
Nov 24, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-29002 MEDIUM
MediaWiki < 1.35 - Cross-Site Scripting via CologneBlue Skin qbfind Message
Nov 24, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-27957 MEDIUM
MediaWiki < 1.35 - Stored Cross-Site Scripting in RandomGameUnit Extension
Oct 28, 2020
CVSS 5.4
EPSS 0.00