Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2020-35626
An issue exists in the PushToWatch extension for MediaWiki up to and including 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.
Mediawiki Mediawiki
6.8
CVSSv2
CVE-2019-15150
In the OAuth2 Client extension prior to 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
Schine.games Mw-oauth2client
6.8
CVSSv2
CVE-2019-12466
Wikimedia MediaWiki up to and including 1.32.1 allows CSRF.
Mediawiki Mediawiki
Debian Debian Linux 9.0
6.8
CVSSv2
CVE-2017-0362
Mediawiki prior to 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
Mediawiki Mediawiki
Debian Debian Linux 7.0
6.8
CVSSv2
CVE-2015-8623
The User::matchEditToken function in includes/User.php in MediaWiki prior to 1.23.12 and 1.24.x prior to 1.24.5 does not perform token comparison in constant time before returning, which allows remote malicious users to guess the edit token and bypass CSRF protection via a timing...
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki 1.24.4
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki
6.8
CVSSv2
CVE-2015-8624
The User::matchEditToken function in includes/User.php in MediaWiki prior to 1.23.12, 1.24.x prior to 1.24.5, 1.25.x prior to 1.25.4, and 1.26.x prior to 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which al...
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki 1.24.4
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.25.2
Mediawiki Mediawiki 1.26.0
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
Mediawiki Mediawiki 1.25.3
Mediawiki Mediawiki
6.8
CVSSv2
CVE-2015-8002
The chunked upload API (ApiUpload) in MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks.
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.25.2
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
6.8
CVSSv2
CVE-2015-8003
MediaWiki prior to 1.23.11, 1.24.x prior to 1.24.4, and 1.25.x prior to 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
Mediawiki Mediawiki 1.24.2
Mediawiki Mediawiki 1.24.3
Mediawiki Mediawiki
Mediawiki Mediawiki 1.24.0
Mediawiki Mediawiki 1.24.1
Mediawiki Mediawiki 1.25.2
Mediawiki Mediawiki 1.25.1
Mediawiki Mediawiki 1.25.0
6.8
CVSSv2
CVE-2015-2940
Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote malicious users to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.
Mediawiki Checkuser -
6.8
CVSSv2
CVE-2014-5241
The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki prior to 1.19.18, 1.20.x up to and including 1.22.x prior to 1.22.9, and 1.23.x prior to 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote ...
Mediawiki Mediawiki 1.23.0
Mediawiki Mediawiki 1.22.8
Mediawiki Mediawiki 1.19
Mediawiki Mediawiki 1.19.8
Mediawiki Mediawiki 1.20.5
Mediawiki Mediawiki 1.20.1
Mediawiki Mediawiki 1.22.6
Mediawiki Mediawiki 1.21.8
Mediawiki Mediawiki 1.22.0
Mediawiki Mediawiki 1.19.3
Mediawiki Mediawiki 1.19.15
Mediawiki Mediawiki 1.22.5
Mediawiki Mediawiki 1.19.1
Mediawiki Mediawiki 1.23.1
Mediawiki Mediawiki 1.21.5
Mediawiki Mediawiki 1.20.4
Mediawiki Mediawiki 1.20.2
Mediawiki Mediawiki 1.19.10
Mediawiki Mediawiki 1.21.6
Mediawiki Mediawiki 1.21.1
Mediawiki Mediawiki 1.22.7
Mediawiki Mediawiki 1.21.10
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »