← Back

Mediawiki

mediawiki

453 CVEs • 18 products

Products (18)

Click to collapse
Toggle
Mediawiki
mediawiki
Cargo
cargo
Checkuser
checkuser
Abusefilter
abusefilter
Visual Editor
visual_editor
Mediawik
mediawik
Rssreader
rssreader
Scribunto
scribunto
Skin\
skin\
Createredirect
createredirect
Matomo
matomo
Score
score

CVEs (453)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mediawiki
1Mediawiki
Jun 17, 2026
Feb 3, 2026
0.0 NONE· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HT...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Feb 3, 2026
0.0 NONE· v4
3.1 LOW· v3
N/A· v2
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
1Mediawiki
1Cargo
Jun 17, 2026
Oct 5, 2024
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X befor...Show more
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.Show less
1Mediawiki
1Cargo
Jun 17, 2026
Oct 5, 2024
6.9 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Car...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.Show less
1Mediawiki
1Cargo
Jun 17, 2026
Oct 5, 2024
6.9 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
1Mediawiki
1Mediawiki
Jun 17, 2026
Oct 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the...Show more
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.)
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 7, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
May 5, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrat...Show more
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.Show less
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
May 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for...Show more
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.Show less
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
May 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even...Show more
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.Show less
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
May 5, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not e...Show more
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.Show less