mediawiki

431 tracked vulnerabilities.

CVE-2020-27621 MEDIUM
MediaWiki <1.35.0 - Info Disclosure
Oct 22, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-27620 MEDIUM
Cosmos Skin for MediaWiki <1.35.0 - XSS
Oct 22, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-26121 HIGH
MediaWiki < 1.34.4 - Incorrect Authorization in FileImporter Extension
Sep 27, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-26120 MEDIUM
MediaWiki < 1.34.4 - Cross-Site Scripting via MobileFrontend Section Line Regex Replacement
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25869 HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Information Leak via Actor ID Handling
Sep 27, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-25828 MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Cross-Site Scripting in Message Parser
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25827 HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Improper Restriction of Excessive Authentication Attempts
Sep 27, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-25815 MEDIUM
MediaWiki 1.32.0-1.34.3 - Cross-Site Scripting in LogEventList::getFiltersDesc
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25814 MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Stored Cross-Site Scripting via jQuery Message Parsing
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25813 MEDIUM
MediaWiki <1.31.10-1.34.4 - Info Disclosure
Sep 27, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-25812 MEDIUM
MediaWiki 1.34.0-1.34.3 - Cross-Site Scripting via Special:Contributions NS Filter
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-15005 LOW
MediaWiki <1.31.8-1.34.2 - Info Disclosure
Jun 24, 2020
CVSS 3.1
EPSS 0.01
CVE-2020-10959 MEDIUM
MediaWiki < 1.35 - Unauthenticated Open Redirect via HTML Content in Page
Jun 02, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-12051 HIGH
MediaWiki CentralAuth Extension - Information Disclosure via API Global User Info Query
Apr 21, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-10960 MEDIUM
MediaWiki <1.34.1 - Info Disclosure
Apr 03, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-10534 CRITICAL
MediaWiki <1.34.0 - Privilege Escalation
Mar 12, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-6163 MEDIUM
WikibaseMediaInfo extension 1.35 - XSS
Jan 08, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-16528 HIGH
MediaWiki AbuseFilter - Sensitive Information Exposure in AbuseLog Revision Data
Mar 20, 2020
CVSS 7.5
EPSS 0.00
CVE-2019-16529 MEDIUM
MediaWiki CheckUser <1.35.0 - Info Disclosure
Mar 19, 2020
CVSS 5.3
EPSS 0.00
CVE-2019-15124 MEDIUM
MobileFrontend REL1_31-REL1_33 - Cross-Site Scripting in Watchlist Feed Edit Summary
Mar 19, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-19910 MEDIUM
MediaWiki MinervaNeue Skin - Stored Cross-Site Scripting via IMG HTML Attributes
Dec 19, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-19709 MEDIUM
MediaWiki < 1.33.1 - Open Redirect via Title Blacklist Bypass
Dec 11, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-19708 MEDIUM
MediaWiki VisualEditor < 1.34 - Cross-Site Scripting via Pasted Content with data-ve-clipboard-key Attribute
Dec 11, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-18987 MEDIUM
MediaWiki AbuseFilter <1.34 - Info Disclosure
Nov 15, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-18612 MEDIUM
MediaWiki AbuseFilter <1.34 - Info Disclosure
Oct 29, 2019
CVSS 5.3
EPSS 0.00