Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki 1.22.1 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2013-6451
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 prior to 1.19.10, 1.2x prior to 1.21.4, and 1.22.x prior to 1.22.1 allows remote malicious users to inject arbitrary web script or HTML via unspecified CSS values.
Mediawiki Mediawiki
5.3
CVSSv3
CVE-2013-6455
The CentralAuth extension for MediaWiki prior to 1.19.10, 1.2x prior to 1.21.4, and 1.22.x prior to 1.22.1 allows remote malicious users to obtain usernames via vectors related to writing the names to the DOM of a page.
Mediawiki Mediawiki
9.8
CVSSv3
CVE-2014-9487
The getid3 library in MediaWiki prior to 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote malicious users to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to CVE-2014-2053.
Mediawiki Mediawiki 1.19.1
Mediawiki Mediawiki 1.19.3
Mediawiki Mediawiki 1.19.10
Mediawiki Mediawiki 1.19.12
Mediawiki Mediawiki 1.19.17
Mediawiki Mediawiki 1.19.19
Mediawiki Mediawiki 1.19.4
Mediawiki Mediawiki 1.19.5
Mediawiki Mediawiki 1.19.6
Mediawiki Mediawiki 1.19.7
Mediawiki Mediawiki 1.19.8
Mediawiki Mediawiki 1.19.21
Mediawiki Mediawiki 1.19.22
Mediawiki Mediawiki 1.19
Mediawiki Mediawiki 1.19.13
Mediawiki Mediawiki 1.19.14
Mediawiki Mediawiki 1.19.15
Mediawiki Mediawiki 1.19.16
Mediawiki Mediawiki 1.19.0
Mediawiki Mediawiki 1.19.2
Mediawiki Mediawiki 1.19.9
Mediawiki Mediawiki 1.19.11
NA
CVE-2015-2934
MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote malicious users to inject arbitrary web script or HTML via a crafted SVG file.
Mediawiki Mediawiki 1.20.5
Mediawiki Mediawiki
Mediawiki Mediawiki 1.20.7
Mediawiki Mediawiki 1.20.8
Mediawiki Mediawiki 1.21.6
Mediawiki Mediawiki 1.21.7
Mediawiki Mediawiki 1.22.2
Mediawiki Mediawiki 1.22.3
Mediawiki Mediawiki 1.22.4
Mediawiki Mediawiki 1.22.11
Mediawiki Mediawiki 1.22.12
Mediawiki Mediawiki 1.23.3
Mediawiki Mediawiki 1.23.4
Mediawiki Mediawiki 1.20
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.20.2
Mediawiki Mediawiki 1.21
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.8
Mediawiki Mediawiki 1.21.9
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.22.6
NA
CVE-2015-2938
Cross-site scripting (XSS) vulnerability in MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2 allows remote malicious users to inject arbitrary web script or HTML via a custom JavaScript file, which is not properly handled when previewing the file.
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.20.2
Mediawiki Mediawiki 1.21
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.9
Mediawiki Mediawiki 1.21.10
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.22.6
Mediawiki Mediawiki 1.22.13
Mediawiki Mediawiki 1.22.14
Mediawiki Mediawiki 1.23.6
Mediawiki Mediawiki 1.23.7
Mediawiki Mediawiki 1.20.5
Mediawiki Mediawiki 1.20.6
Mediawiki Mediawiki 1.21.4
Mediawiki Mediawiki 1.21.5
Mediawiki Mediawiki 1.21.6
Mediawiki Mediawiki 1.22.1
Mediawiki Mediawiki 1.22.2
Mediawiki Mediawiki 1.22.9
Mediawiki Mediawiki 1.22.10
Mediawiki Mediawiki 1.23.2
NA
CVE-2015-2942
MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2, when using HHVM, allows remote malicious users to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an (1) SVG file or (2) XMP metadata in a PDF fi...
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.20.2
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.2
Mediawiki Mediawiki 1.21.9
Mediawiki Mediawiki 1.21.10
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.22.6
Mediawiki Mediawiki 1.22.14
Mediawiki Mediawiki 1.22.15
Mediawiki Mediawiki 1.23.6
Mediawiki Mediawiki 1.23.7
Mediawiki Mediawiki 1.20.5
Mediawiki Mediawiki 1.20.6
Mediawiki Mediawiki 1.21.5
Mediawiki Mediawiki 1.21.6
Mediawiki Mediawiki 1.22.1
Mediawiki Mediawiki 1.22.2
Mediawiki Mediawiki 1.22.9
Mediawiki Mediawiki 1.22.10
Mediawiki Mediawiki 1.22.11
Mediawiki Mediawiki 1.23.2
NA
CVE-2015-2931
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2 allows remote malicious users to inject arbitrary web script or HTML via an application/xml MIME type for a nested SVG with a data:...
Mediawiki Mediawiki 1.20
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.21
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.8
Mediawiki Mediawiki 1.21.9
Mediawiki Mediawiki 1.22.4
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.22.13
Mediawiki Mediawiki 1.22.14
Mediawiki Mediawiki 1.23.5
Mediawiki Mediawiki 1.23.6
Mediawiki Mediawiki 1.20.4
Mediawiki Mediawiki 1.20.5
Mediawiki Mediawiki 1.21.4
Mediawiki Mediawiki 1.21.5
Mediawiki Mediawiki 1.22.0
Mediawiki Mediawiki 1.22.1
Mediawiki Mediawiki 1.22.8
Mediawiki Mediawiki 1.22.9
Mediawiki Mediawiki 1.22.10
Mediawiki Mediawiki 1.23.1
NA
CVE-2015-2932
Incomplete blacklist vulnerability in MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2 allows remote malicious users to inject arbitrary web script or HTML via an animated href XLink element.
Mediawiki Mediawiki 1.20
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.21
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.8
Mediawiki Mediawiki 1.21.9
Mediawiki Mediawiki 1.22.4
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.22.6
Mediawiki Mediawiki 1.22.13
Mediawiki Mediawiki 1.22.14
Mediawiki Mediawiki 1.23.5
Mediawiki Mediawiki 1.23.6
Mediawiki Mediawiki 1.20.5
Mediawiki Mediawiki 1.20.6
Mediawiki Mediawiki 1.21.4
Mediawiki Mediawiki 1.21.5
Mediawiki Mediawiki 1.22.0
Mediawiki Mediawiki 1.22.1
Mediawiki Mediawiki 1.22.9
Mediawiki Mediawiki 1.22.10
Mediawiki Mediawiki 1.23.1
NA
CVE-2015-2933
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2 allows remote malicious users to inject arbitrary web script or HTML via a LanguageConverter substitution string when using a language varian...
Mediawiki Mediawiki 1.20.2
Mediawiki Mediawiki 1.20.3
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.2
Mediawiki Mediawiki 1.21.3
Mediawiki Mediawiki 1.21.10
Mediawiki Mediawiki 1.21.11
Mediawiki Mediawiki 1.22.6
Mediawiki Mediawiki 1.22.7
Mediawiki Mediawiki 1.22.15
Mediawiki Mediawiki 1.23.0
Mediawiki Mediawiki 1.23.7
Mediawiki Mediawiki 1.23.8
Mediawiki Mediawiki
Mediawiki Mediawiki 1.20.6
Mediawiki Mediawiki 1.20.7
Mediawiki Mediawiki 1.21.6
Mediawiki Mediawiki 1.21.7
Mediawiki Mediawiki 1.22.2
Mediawiki Mediawiki 1.22.3
Mediawiki Mediawiki 1.22.10
Mediawiki Mediawiki 1.22.11
NA
CVE-2015-2935
MediaWiki prior to 1.19.24, 1.2x prior to 1.23.9, and 1.24.x prior to 1.24.2 allows remote malicious users to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."
Mediawiki Mediawiki
Mediawiki Mediawiki 1.20
Mediawiki Mediawiki 1.20.7
Mediawiki Mediawiki 1.20.8
Mediawiki Mediawiki 1.21.6
Mediawiki Mediawiki 1.21.7
Mediawiki Mediawiki 1.22.3
Mediawiki Mediawiki 1.22.4
Mediawiki Mediawiki 1.22.11
Mediawiki Mediawiki 1.22.12
Mediawiki Mediawiki 1.23.3
Mediawiki Mediawiki 1.23.4
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.20.2
Mediawiki Mediawiki 1.21
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.21.8
Mediawiki Mediawiki 1.21.9
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.22.6
Mediawiki Mediawiki 1.22.13
Mediawiki Mediawiki 1.22.14
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »