CVEs (417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML. |
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file). |
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client...Show more |
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) ch...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Dec 11, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in th...Show more |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 31, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. |
mediawiki allows deleted text to be exposed |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Sep 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. |
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 an...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Wikimedia MediaWiki through 1.32.1 allows CSRF. |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeov...Show more |
2Debian Mediawiki2Debian Linux MediawikiJun 17, 2026 Jul 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. |
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible. |