← Back

Mediawiki

mediawiki

Vendor: Mediawiki • 417 CVEs

CVEs (417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
1Mediawiki
1Mediawiki
Nov 21, 2024
Apr 16, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
May 13, 2026
Dec 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an exist...Show more
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
2Debian
Mediawiki
2Debian Linux
Mediawiki
May 13, 2026
Nov 15, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.