Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2023-37304
An issue exists in the DoubleWiki extension for MediaWiki up to and including 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature.
Mediawiki Mediawiki
5.3
CVSSv3
CVE-2023-37305
An issue exists in the ProofreadPage (aka Proofread Page) extension for MediaWiki up to and including 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.
Mediawiki Mediawiki
6.1
CVSSv3
CVE-2023-37251
An issue exists in the GoogleAnalyticsMetrics extension for MediaWiki up to and including 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
Mediawiki Mediawiki
6.1
CVSSv3
CVE-2023-37254
An issue exists in the Cargo extension for MediaWiki up to and including 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
Mediawiki Mediawiki
6.1
CVSSv3
CVE-2023-37255
An issue exists in the CheckUser extension for MediaWiki up to and including 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
Mediawiki Mediawiki
6.1
CVSSv3
CVE-2023-37256
An issue exists in the Cargo extension for MediaWiki up to and including 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
Mediawiki Mediawiki
6.1
CVSSv3
CVE-2023-36675
An issue exists in MediaWiki prior to 1.35.11, 1.36.x up to and including 1.38.x prior to 1.38.7, and 1.39.x prior to 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Mediawiki Mediawiki
4.3
CVSSv3
CVE-2022-41766
An issue exists in MediaWiki prior to 1.35.8, 1.36.x and 1.37.x prior to 1.37.5, and 1.38.x prior to 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).
Mediawiki Mediawiki
9.8
CVSSv3
CVE-2020-29007
The Score extension up to and including 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execut...
Mediawiki Score
5 Github repositories
4.3
CVSSv3
CVE-2021-30153
An issue exists in the VisualEditor extension in MediaWiki prior to 1.31.13, and 1.32.x up to and including 1.35.x prior to 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists....
Mediawiki Mediawiki
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »