Skip to main content

Vendor archive

mediawiki CVEs

Beta · best-effort

463 CVEs tagged to vendor mediawiki19 Critical, 73 High, 314 Medium, 27 Low, 30 Unrated.

CVE-2009-4589

Published Jan 7, 2010

Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote att…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0737

Published Feb 25, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5688

Published Dec 19, 2008

MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetails variable is enabled, sometimes provides the full installation path in a debugging message, which…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5687

Published Dec 19, 2008

MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensiti…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5252

Published Dec 19, 2008

Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attac…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5250

Published Dec 19, 2008

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and 1.13.x before 1.13.3, when Internet Explorer is used and uploads are enabled, or an…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5249

Published Dec 19, 2008

Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.0 through 1.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4408

Published Oct 3, 2008

Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1318

Published Mar 13, 2008

Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback parameter in an API call for JavaSc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4883

Published Sep 14, 2007

Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4828

Published Sep 12, 2007

Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through 1.9.3, 1.10.0 through 1.10.1, and the 1.11 development ver…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1054

Published Feb 21, 2007

Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrar…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1055

Published Feb 21, 2007

Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary we…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0894

Published Feb 12, 2007

MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0788

Published Feb 6, 2007

Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "sortabl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0177

Published Jan 11, 2007

Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allo…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2895

Published Jun 7, 2006

Cross-site scripting (XSS) vulnerability in MediaWiki 1.6.0 up to versions before 1.6.7 allows remote attackers to inject arbitrary HTML and web script via the edit form.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2611

Published May 26, 2006

Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14349 allows remote attackers to inject arbitrary Javascript…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1498

Published Mar 30, 2006

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0322

Published Jan 19, 2006

Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4501

Published Dec 22, 2005

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute J…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4031

Published Dec 6, 2005

Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynam…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3165

Published Oct 6, 2005

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3166

Published Oct 6, 2005

Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 463 CVEsPage 18 of 19