Skip to main content

Vendor archive

mediawiki CVEs

Beta · best-effort

463 CVEs tagged to vendor mediawiki19 Critical, 73 High, 314 Medium, 27 Low, 30 Unrated.

CVE-2024-40605

Published Jul 7, 2024

An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40604

Published Jul 7, 2024

An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40603

Published Jul 7, 2024

An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40602

Published Jul 7, 2024

An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40601

Published Jul 7, 2024

An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40600

Published Jul 7, 2024

An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40599

Published Jul 7, 2024

An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40598

Published Jul 7, 2024

An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40597

Published Jul 7, 2024

An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.)

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40596

Published Jul 7, 2024

An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34507

Published May 5, 2024

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishand…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34506

Published May 5, 2024

An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34502

Published May 5, 2024

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-34500

Published May 5, 2024

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. E…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23179

Published Jan 12, 2024

An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses messa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23178

Published Jan 12, 2024

An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23177

Published Jan 12, 2024

An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23174

Published Jan 12, 2024

An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23173

Published Jan 12, 2024

An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows XSS vi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23172

Published Jan 12, 2024

An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definition…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23171

Published Jan 12, 2024

An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51704

Published Dec 22, 2023

An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member mess…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45362

Published Nov 3, 2023

An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45360

Published Nov 3, 2023

An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessa…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45374

Published Oct 9, 2023

An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CS…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 463 CVEsPage 4 of 19