mediawiki
431 tracked vulnerabilities.
CVE-2020-27621
MEDIUM
MediaWiki <1.35.0 - Info Disclosure
Oct 22, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-27620
MEDIUM
Cosmos Skin for MediaWiki <1.35.0 - XSS
Oct 22, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-26121
HIGH
MediaWiki < 1.34.4 - Incorrect Authorization in FileImporter Extension
Sep 27, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-26120
MEDIUM
MediaWiki < 1.34.4 - Cross-Site Scripting via MobileFrontend Section Line Regex Replacement
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25869
HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Information Leak via Actor ID Handling
Sep 27, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-25828
MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Cross-Site Scripting in Message Parser
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25827
HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Improper Restriction of Excessive Authentication Attempts
Sep 27, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-25815
MEDIUM
MediaWiki 1.32.0-1.34.3 - Cross-Site Scripting in LogEventList::getFiltersDesc
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25814
MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Stored Cross-Site Scripting via jQuery Message Parsing
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-25813
MEDIUM
MediaWiki <1.31.10-1.34.4 - Info Disclosure
Sep 27, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-25812
MEDIUM
MediaWiki 1.34.0-1.34.3 - Cross-Site Scripting via Special:Contributions NS Filter
Sep 27, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-15005
LOW
MediaWiki <1.31.8-1.34.2 - Info Disclosure
Jun 24, 2020
CVSS 3.1
EPSS 0.01
CVE-2020-10959
MEDIUM
MediaWiki < 1.35 - Unauthenticated Open Redirect via HTML Content in Page
Jun 02, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-12051
HIGH
MediaWiki CentralAuth Extension - Information Disclosure via API Global User Info Query
Apr 21, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-10960
MEDIUM
MediaWiki <1.34.1 - Info Disclosure
Apr 03, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-10534
CRITICAL
MediaWiki <1.34.0 - Privilege Escalation
Mar 12, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-6163
MEDIUM
WikibaseMediaInfo extension 1.35 - XSS
Jan 08, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-16528
HIGH
MediaWiki AbuseFilter - Sensitive Information Exposure in AbuseLog Revision Data
Mar 20, 2020
CVSS 7.5
EPSS 0.00
CVE-2019-16529
MEDIUM
MediaWiki CheckUser <1.35.0 - Info Disclosure
Mar 19, 2020
CVSS 5.3
EPSS 0.00
CVE-2019-15124
MEDIUM
MobileFrontend REL1_31-REL1_33 - Cross-Site Scripting in Watchlist Feed Edit Summary
Mar 19, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-19910
MEDIUM
MediaWiki MinervaNeue Skin - Stored Cross-Site Scripting via IMG HTML Attributes
Dec 19, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-19709
MEDIUM
MediaWiki < 1.33.1 - Open Redirect via Title Blacklist Bypass
Dec 11, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-19708
MEDIUM
MediaWiki VisualEditor < 1.34 - Cross-Site Scripting via Pasted Content with data-ve-clipboard-key Attribute
Dec 11, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-18987
MEDIUM
MediaWiki AbuseFilter <1.34 - Info Disclosure
Nov 15, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-18612
MEDIUM
MediaWiki AbuseFilter <1.34 - Info Disclosure
Oct 29, 2019
CVSS 5.3
EPSS 0.00
Products
mediawiki 395
core 29
cargo 9
checkuser 8
abusefilter 3
visual_editor 3
mobilefrontend 2
abuse-filter 1
createredirect 1
data-transfer 1
matomo 1
mediawik 1
mediawiki_botquery_ext 1
rss_for_mediawiki 1
rssreader 1
score 1
scribunto 1
semantic-media-wiki 1
semantic_drilldown 1
shortdescription 1
skin\ 1
wikisource_category_browser 1
Quick Filters