Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki 1.27.2 vulnerabilities and exploits
(subscribe to this query)
790
VMScore
CVE-2017-0372
Parameters injection in the SyntaxHighlight extension of Mediawiki prior to 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
Mediawiki Mediawiki 1.27.1
Mediawiki Mediawiki 1.28.0
Mediawiki Mediawiki
Mediawiki Mediawiki 1.27.2
Mediawiki Mediawiki 1.27.0
Mediawiki Mediawiki 1.28.1
Debian Debian Linux 9.0
Debian Debian Linux 7.0
445
VMScore
CVE-2017-0371
MediaWiki prior to 1.23.16, 1.24.x up to and including 1.27.x prior to 1.27.2, and 1.28.x prior to 1.28.1 allows remote malicious users to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an...
Mediawiki Mediawiki
516
VMScore
CVE-2017-0364
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
Mediawiki Mediawiki
Debian Debian Linux 7.0
516
VMScore
CVE-2017-0363
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
Mediawiki Mediawiki
Debian Debian Linux 7.0
445
VMScore
CVE-2017-0368
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
Mediawiki Mediawiki
Debian Debian Linux 7.0
356
VMScore
CVE-2017-0366
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
Mediawiki Mediawiki
Debian Debian Linux 7.0
187
VMScore
CVE-2017-0361
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
Mediawiki Mediawiki
Debian Debian Linux 7.0
605
VMScore
CVE-2017-0362
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
Mediawiki Mediawiki
Debian Debian Linux 7.0
445
VMScore
CVE-2017-0370
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
Mediawiki Mediawiki
Debian Debian Linux 7.0
356
VMScore
CVE-2017-0369
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
Mediawiki Mediawiki
Debian Debian Linux 7.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »