CVE-2023-36675

MEDIUM

MediaWiki <1.35.11, <1.36-1.38.7, <1.39.4 - XSS

Title source: llm
STIX 2.1

Description

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.

Scores

CVSS v3 6.1
EPSS 0.0053
EPSS Percentile 67.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
mediawiki/mediawiki < 1.35.11
Published Jun 26, 2023
Tracked Since Feb 18, 2026