Mediawiki
mediawiki
453 CVEs • 18 products
Products (18)
Click to collapseToggle
Products (18)
Click to collapse
CVEs (453)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log da...Show more |
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain deleted MediaWiki usernames, related to rev_deleted. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget(...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently hav...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Apr 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS. |
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure. |
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack. |
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLink...Show more |
An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or M...Show more |
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded. |
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username....Show more |
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are h...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibi...Show more |