VYPR

Mediawiki

by MediaWiki

Source repositories

CVEs (417)

  • CVE-2021-42042MedOct 6, 2021
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and…

  • CVE-2021-36131MedJul 2, 2021
    risk 0.31cvss 4.8epss 0.00

    An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages for many users.

  • CVE-2021-36130MedJul 2, 2021
    risk 0.31cvss 4.8epss 0.01

    An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could…

  • CVE-2020-29002MedNov 24, 2020
    risk 0.31cvss 4.8epss 0.01

    includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supplied by an administrator.

  • CVE-2017-0365MedApr 13, 2018
    risk 0.31cvss 4.7epss 0.01

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.

  • CVE-2026-58026MedJul 1, 2026
    risk 0.30cvss 5.7epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Parser/Parser.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

  • CVE-2026-58024MedJul 1, 2026
    risk 0.30cvss 5.7epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiUserrights.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

  • CVE-2022-28201MedSep 19, 2022
    risk 0.29cvss 4.4epss 0.00

    An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.

  • CVE-2026-58028MedJul 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth. This vulnerability is associated with program files includes/Api/ApiFormatBase.Php,…

  • CVE-2025-67476MedFeb 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.

  • CVE-2024-40603MedJul 7, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.

  • CVE-2024-40598MedJul 7, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)

  • CVE-2024-40596MedJul 7, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)

  • CVE-2023-45362MedNov 3, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak.

  • CVE-2023-45369MedOct 9, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in the PageTriage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. Usernames of hidden users are exposed.

  • CVE-2022-41766MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).

  • CVE-2021-30153MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It…

  • CVE-2023-29137MedMar 31, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.

  • CVE-2023-22945MedJan 11, 2023
    risk 0.28cvss 4.3epss 0.01

    In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.

  • CVE-2022-29905MedApr 29, 2022
    risk 0.28cvss 4.3epss 0.00

    The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.

Page 13 of 21