VYPR

Mediawiki

by MediaWiki

Source repositories

CVEs (417)

  • CVE-2021-45038MedDec 17, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

  • CVE-2021-31554MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically created MediaWiki user accounts, thus allowing nefarious users to remain unblocked.

  • CVE-2021-31552MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create…

  • CVE-2021-31550MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a malicious actor could introduce XSS payloads into various layers.

  • CVE-2021-31545MedApr 22, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain deleted MediaWiki usernames, related to rev_deleted.

  • CVE-2021-30158MedApr 6, 2021
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been…

  • CVE-2020-35624MedDec 21, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.

  • CVE-2020-35480MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about…

  • CVE-2020-35477MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.02

    MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox)…

  • CVE-2020-29003MedNov 24, 2020
    risk 0.35cvss 5.4epss 0.01

    The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Special:CreatePoll or Special:UpdatePoll.

  • CVE-2020-27957MedOct 28, 2020
    risk 0.35cvss 5.4epss 0.01

    The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

  • CVE-2020-25813MedSep 27, 2020
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.

  • CVE-2020-10960MedApr 3, 2020
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows…

  • CVE-2013-6455MedJan 28, 2020
    risk 0.35cvss 5.3epss 0.01

    The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

  • CVE-2019-16738MedSep 26, 2019
    risk 0.35cvss 5.3epss 0.02

    In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.

  • CVE-2019-12467MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.01

    MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2018-13258MedOct 4, 2018
    risk 0.35cvss 5.3epss 0.02

    Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.

  • CVE-2014-1686MedApr 16, 2018
    risk 0.35cvss 5.3epss 0.02

    MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.

  • CVE-2017-0370MedApr 13, 2018
    risk 0.35cvss 5.3epss 0.01

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.

  • CVE-2017-0368MedApr 13, 2018
    risk 0.35cvss 5.3epss 0.02

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

Page 10 of 21