mediawiki
431 tracked vulnerabilities.
CVE-2021-31545
MEDIUM
MediaWiki < 1.35.2 - Exposure of Deleted Usernames via AbuseFilter page_recent_contributors
Apr 22, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-30159
MEDIUM
MediaWiki < 1.31.12 and 1.32.x-1.35.x < 1.35.2 - Unintended Page Deletion via Fast Double Move
Apr 09, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-30156
MEDIUM
MediaWiki <1.35.2 - Info Disclosure
Apr 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-30155
MEDIUM
MediaWiki <1.35.2 - Privilege Escalation
Apr 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-30152
MEDIUM
MediaWiki <1.31.13, 1.32-1.35.1 - Privilege Escalation
Apr 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-30158
MEDIUM
MediaWiki <1.35.2 - Info Disclosure
Apr 06, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-30157
MEDIUM
MediaWiki < 1.31.12 and 1.32.x-1.35.x < 1.35.2 - Stored Cross-Site Scripting in ChangesList Filter Labels
Apr 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-30154
MEDIUM
MediaWiki < 1.31.12 and 1.32.x-1.35.x < 1.35.2 - Cross-Site Scripting via Special:NewFiles
Apr 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2020-29007
CRITICAL
MediaWiki Score < 0.3.0 - Remote Code Execution via GNU LilyPond Sandbox Escape
Apr 15, 2023
CVSS 9.8
EPSS 0.25
CVE-2020-29005
HIGH
MediaWiki < 1.35 - Cleartext Transmission of Sensitive Information in Push Extension API
Jan 29, 2021
CVSS 7.5
EPSS 0.00
CVE-2020-29004
HIGH
MediaWiki < 1.35 - Cross-Site Request Forgery via Push Extension API
Jan 29, 2021
CVSS 8.8
EPSS 0.00
CVE-2020-35626
HIGH
MediaWiki < 1.35.1 - Cross-Site Request Forgery in PushToWatch Extension
Dec 21, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-35625
HIGH
MediaWiki < 1.35.1 - Unauthenticated Arbitrary Static Function Execution via Widgets Extension HTML Comment
Dec 21, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-35624
MEDIUM
MediaWiki < 1.35.1 - Information Disclosure via SecurePoll Vote Timestamp
Dec 21, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-35623
HIGH
MediaWiki <1.35.1 - Privilege Escalation
Dec 21, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-35622
MEDIUM
MediaWiki GlobalUsage Extension < 1.35.1 - Cross-Site Scripting via Unsafe WikiMap Link Generation
Dec 21, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-35480
MEDIUM
MediaWiki < 1.35.1 - Information Disclosure of Hidden User Accounts
Dec 18, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-35479
MEDIUM
MediaWiki 1.12.0-1.35.0 - Cross-Site Scripting via BlockLogFormatter.php
Dec 18, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-35478
MEDIUM
MediaWiki 1.33.0-1.35.0 - Cross-Site Scripting via BlockLogFormatter.php
Dec 18, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-35477
MEDIUM
MediaWiki <1.35.1 - Info Disclosure
Dec 18, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-35475
HIGH
MediaWiki < 1.35.1 - Cross-Site Scripting in UserRights Special Page
Dec 18, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-35474
MEDIUM
MediaWiki < 1.35.1 - Stored Cross-Site Scripting via MediaWiki:recentchanges-legend-watchlistexpiry
Dec 18, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-29003
MEDIUM
MediaWiki PollNY extension < 1.35 - Stored Cross-Site Scripting via Poll Answer Option
Nov 24, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-29002
MEDIUM
MediaWiki < 1.35 - Cross-Site Scripting via CologneBlue Skin qbfind Message
Nov 24, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-27957
MEDIUM
MediaWiki < 1.35 - Stored Cross-Site Scripting in RandomGameUnit Extension
Oct 28, 2020
CVSS 5.4
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters