Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki 1.25.1 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2015-6729
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki prior to 1.23.10, 1.24.x prior to 1.24.3, and 1.25.x prior to 1.25.2 allows remote malicious users to inject arbitrary web script or HTML via the rel404 parameter, which is not properly handled in an error page.
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
4.3
CVSSv2
CVE-2015-6730
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki prior to 1.23.10, 1.24.x prior to 1.24.3, and 1.25.x prior to 1.25.2 allows remote malicious users to inject arbitrary web script or HTML via the f parameter, which is not properly handled in an error page, relate...
Mediawiki Mediawiki
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.2
5
CVSSv2
CVE-2015-6733
GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki prior to 1.23.10, 1.24.x prior to 1.24.3, and 1.25.x prior to 1.25.2, allows remote malicious users to cause a denial of service (resource consumption) via unspecified vectors.
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki
4.3
CVSSv2
CVE-2015-6734
Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki prior to 1.23.10, 1.24.x prior to 1.24.3, and 1.25.x prior to 1.25.2, allows remote malicious users to inject arbitrary web script or HTML via...
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.2
7.5
CVSSv2
CVE-2015-6728
The ApiBase::getWatchlistUser function in MediaWiki prior to 1.23.10, 1.24.x prior to 1.24.3, and 1.25.x prior to 1.25.2 does not perform token comparison in constant time, which allows remote malicious users to guess the watchlist token and bypass CSRF protection via a timing at...
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
4
CVSSv2
CVE-2015-8004
MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which ret...
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.2
3.5
CVSSv2
CVE-2015-8001
The chunked upload API (ApiUpload) in MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the fil...
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.2
6.8
CVSSv2
CVE-2015-8002
The chunked upload API (ApiUpload) in MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks.
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.2
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.1
6.8
CVSSv2
CVE-2015-8003
MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.2
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
5
CVSSv2
CVE-2015-8005
MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote malicious users to obtain the installation path by reading the metadata of a PNG thumbnail file.
Mediawiki Mediawiki
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.2
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.25.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »