CVE-2007-4828
Mediawiki - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development versions before 1.11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (8)
Scores
EPSS
0.0054
EPSS Percentile
67.2%
Classification
CWE
CWE-79
Status
draft
Affected Products (12)
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
Timeline
Published
Sep 12, 2007
Tracked Since
Feb 18, 2026