VYPR

Widgets

by MediaWiki

CVEs (3)

  • CVE-2020-35625HigDec 21, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty…

  • CVE-2020-9382MedFeb 24, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

  • CVE-2015-6737Sep 1, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content.