Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mediawiki mediawiki 1.20 vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2013-4303
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x prior to 1.19.8, 1.20.x prior to 1.20.7, and 1.21.x prior to 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote ma...
Mediawiki Mediawiki
6.1
CVSSv3
CVE-2013-1951
A cross-site scripting (XSS) vulnerability in MediaWiki prior to 1.19.5 and 1.20.x prior to 1.20.4 and allows remote malicious users to inject arbitrary web script or HTML via Lua function names.
Mediawiki Mediawiki
Debian Debian Linux 10.0
Debian Debian Linux 9.0
7.5
CVSSv3
CVE-2013-4572
The CentralNotice extension for MediaWiki prior to 1.19.9, 1.20.x prior to 1.20.8, and 1.21.x prior to 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote malicious users to authenticate as the created user.
Mediawiki Mediawiki
Fedoraproject Fedora 18
Fedoraproject Fedora 19
7.5
CVSSv3
CVE-2013-1817
MediaWiki prior to 1.19.4 and 1.20.x prior to 1.20.3 contains an error in the api.php script which allows remote malicious users to obtain sensitive information.
Mediawiki Mediawiki
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Redhat Enterprise Linux 6.0
Fedoraproject Fedora 18
7.5
CVSSv3
CVE-2013-1816
MediaWiki prior to 1.19.4 and 1.20.x prior to 1.20.3 allows remote malicious users to cause a denial of service (application crash) by sending a specially crafted request.
Mediawiki Mediawiki
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Redhat Enterprise Linux 6.0
Fedoraproject Fedora 18
NA
CVE-2013-4308
Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x prior to 1.19.8, 1.20.x prior to 1.20.7, and 1.21.x prior to 1.21.2 allows remote malicious users to inject arbitrary web scrip...
Liquidthreads Project Liquidthreads 2.0
Liquidthreads Project Liquidthreads 2.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5