Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-37304
An issue exists in the DoubleWiki extension for MediaWiki up to and including 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature.
Mediawiki Mediawiki
NA
CVE-2023-37305
An issue exists in the ProofreadPage (aka Proofread Page) extension for MediaWiki up to and including 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
Mediawiki Mediawiki
NA
CVE-2023-37251
An issue exists in the GoogleAnalyticsMetrics extension for MediaWiki up to and including 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Mediawiki Mediawiki
NA
CVE-2023-37254
An issue exists in the Cargo extension for MediaWiki up to and including 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
Mediawiki Mediawiki
NA
CVE-2023-37255
An issue exists in the CheckUser extension for MediaWiki up to and including 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
Mediawiki Mediawiki
NA
CVE-2023-37256
An issue exists in the Cargo extension for MediaWiki up to and including 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Mediawiki Mediawiki
NA
CVE-2023-36675
An issue exists in MediaWiki prior to 1.35.11, 1.36.x up to and including 1.38.x prior to 1.38.7, and 1.39.x prior to 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Mediawiki Mediawiki
NA
CVE-2022-41766
An issue exists in MediaWiki prior to 1.35.8, 1.36.x and 1.37.x prior to 1.37.5, and 1.38.x prior to 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).
Mediawiki Mediawiki
NA
CVE-2020-29007
The Score extension up to and including 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execut...
Mediawiki Score
5 Github repositories
NA
CVE-2021-30153
An issue exists in the VisualEditor extension in MediaWiki prior to 1.31.13, and 1.32.x up to and including 1.35.x prior to 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists....
Mediawiki Mediawiki
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »