VYPR
Unrated severityNVD Advisory· Published Sep 1, 2015· Updated May 6, 2026

CVE-2015-6734

CVE-2015-6734

Description

Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

6
  • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*range: <=1.23.9
    • cpe:2.3:a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.