VYPR

Mediawiki

by MediaWiki

Source repositories

CVEs (417)

  • CVE-2022-28204HigSep 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3AP31&namespace=1&invert=1 can take more than thirty seconds. There is a DDoS risk.

  • CVE-2022-28203HigSep 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.

  • CVE-2022-34750HigJun 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thousand characters. Unfortunately, this length is not validated, allowing much larger lexemes to be created, which introduces various denial-of-service attack…

  • CVE-2022-28323HigApr 30, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp is supported,

  • CVE-2017-0371HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.02

    MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the…

  • CVE-2021-46149HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.

  • CVE-2021-44858HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.

  • CVE-2021-41799HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.02

    MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.

  • CVE-2021-42040HigOct 6, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion.

  • CVE-2021-36125HigJul 2, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).

  • CVE-2021-35197HigJul 2, 2021
    risk 0.49cvss 7.5epss 0.02

    In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block"…

  • CVE-2021-31555HigApr 22, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka oauth_registered_consumer.oarc_version) parameter's length.

  • CVE-2020-29005HigJan 29, 2021
    risk 0.49cvss 7.5epss 0.01

    The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

  • CVE-2020-35475HigDec 18, 2020
    risk 0.49cvss 7.5epss 0.02

    In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in…

  • CVE-2020-26121HigSep 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction…

  • CVE-2020-25869HigSep 27, 2020
    risk 0.49cvss 7.5epss 0.01

    An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.

  • CVE-2020-25827HigSep 27, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests…

  • CVE-2020-12051HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the action API even though access…

  • CVE-2013-4572HigFeb 6, 2020
    risk 0.49cvss 7.5epss 0.02

    The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

  • CVE-2013-1817HigNov 20, 2019
    risk 0.49cvss 7.5epss 0.03

    MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.

Page 3 of 21