← Back

Mediawiki

mediawiki

453 CVEs • 18 products

Products (18)

Click to collapse
Toggle
Mediawiki
mediawiki
Cargo
cargo
Checkuser
checkuser
Abusefilter
abusefilter
Visual Editor
visual_editor
Mediawik
mediawik
Rssreader
rssreader
Scribunto
scribunto
Skin\
skin\
Createredirect
createredirect
Matomo
matomo
Score
score

CVEs (453)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mediawiki
1Abusefilter
Jun 17, 2026
Mar 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog...Show more
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog revision data. This affects REL1_32 and REL1_33.Show less
1Mediawiki
1Checkuser
Jun 17, 2026
Mar 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.
1Mediawiki
1Mobilefrontend
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33.
1Mediawiki
1Mediawiki
Jun 17, 2026
Mar 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an I...Show more
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Feb 8, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when...Show more
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.Show less
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to...Show more
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.
1Mediawiki
1Mediawiki
Nov 21, 2024
Jan 28, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
1Mediawiki
1Mediawiki
Nov 21, 2024
Jan 27, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
1Mediawiki
1Mediawiki
Jun 17, 2026
Dec 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client...Show more
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client's IP address). This can occur within a talk page topical header that is viewed within a mobile (MobileFrontend) context.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) ch...Show more
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in th...Show more
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.Show less
1Mediawiki
1Visual Editor
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
4Debian
FedoraprojectMediawiki+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
4Debian
FedoraprojectMediawiki+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
1Mediawiki
1Abusefilter
Jun 17, 2026
Nov 15, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially discl...Show more
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
1Mediawiki
1Abusefilter
Jun 17, 2026
Oct 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosin...Show more
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.Show less
1Mediawiki
1Checkuser
Jun 17, 2026
Oct 29, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with va...Show more
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with various levels of access to this extension. Said users should not have been able to view these oversighted edit summaries via the MediaWiki API.Show less