Skip to main content

Vendor archive

wikimedia CVEs

Beta · best-effort

13 CVEs tagged to vendor wikimedia0 Critical, 0 High, 10 Medium, 2 Low, 1 Unrated.

CVE-2025-61638

Published Feb 3, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid. This vul…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2026-0817

Published Jan 9, 2026

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22710

Published Jan 9, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-S…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0671

Published Jan 8, 2026

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-S…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-47841

Published Oct 5, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47845

Published Oct 5, 2024

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: fro…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47840

Published Oct 5, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25065

Published Jan 5, 2023

A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects some unknown processing of the file I18nTags_body.php of the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36324

Published Apr 21, 2021

Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30458

Published Apr 9, 2021

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta>…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19329

Published Nov 27, 2019

In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19328

Published Nov 27, 2019

ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer b…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19327

Published Nov 27, 2019

ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results and number of milliseconds. NOT…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1