Mediawiki
mediawiki
453 CVEs • 18 products
Products (18)
Click to collapseToggle
Products (18)
Click to collapse
CVEs (453)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext. |
2Fedoraproject Mediawiki2Fedora MediawikiMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an exist...Show more |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk." |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allo...Show more |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping. |
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the...Show more |
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary web script or HTML via a File: link to a nonexistent image. |
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt. |
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors. |