Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-37305
An issue exists in the ProofreadPage (aka Proofread Page) extension for MediaWiki up to and including 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
Mediawiki Mediawiki
NA
CVE-2023-37302
An issue exists in SiteLinksView.php in Wikibase in MediaWiki up to and including 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute)...
Mediawiki Mediawiki
NA
CVE-2023-37304
An issue exists in the DoubleWiki extension for MediaWiki up to and including 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature.
Mediawiki Mediawiki
NA
CVE-2023-37255
An issue exists in the CheckUser extension for MediaWiki up to and including 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
Mediawiki Mediawiki
NA
CVE-2023-37251
An issue exists in the GoogleAnalyticsMetrics extension for MediaWiki up to and including 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Mediawiki Mediawiki
NA
CVE-2023-37254
An issue exists in the Cargo extension for MediaWiki up to and including 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
Mediawiki Mediawiki
NA
CVE-2023-37256
An issue exists in the Cargo extension for MediaWiki up to and including 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Mediawiki Mediawiki
NA
CVE-2023-36675
An issue exists in MediaWiki prior to 1.35.11, 1.36.x up to and including 1.38.x prior to 1.38.7, and 1.39.x prior to 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Mediawiki Mediawiki
NA
CVE-2022-41766
An issue exists in MediaWiki prior to 1.35.8, 1.36.x and 1.37.x prior to 1.37.5, and 1.38.x prior to 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).
Mediawiki Mediawiki
NA
CVE-2020-29007
The Score extension up to and including 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execut...
Mediawiki Score
5 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »