VYPR

Mediawiki

by MediaWiki

Source repositories

CVEs (417)

  • CVE-2026-58033MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/InfoAction.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

  • CVE-2026-58029MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php,…

  • CVE-2026-58027MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

  • CVE-2025-61646MedFeb 3, 2026
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

  • CVE-2024-23178MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

  • CVE-2024-23174MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter-date-range-format-placeh…

  • CVE-2024-23172MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog.

  • CVE-2024-23171MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows XSS via the x-xss language setting for internationalization (i18n).

  • CVE-2023-45360MedNov 3, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.

  • CVE-2023-37304MedJun 30, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature.

  • CVE-2023-37300MedJun 30, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.

  • CVE-2023-22910MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have…

  • CVE-2023-22909MedJan 10, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.

  • CVE-2022-41767MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions…

  • CVE-2022-41765MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.

  • CVE-2021-44855MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

  • CVE-2021-42047MedSep 29, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-mentee-overview-no-js-fallba…

  • CVE-2021-42045MedSep 29, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to create alerts by changing their User-Agent HTTP header and submitting a vote.

  • CVE-2021-46146MedJan 10, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.

  • CVE-2021-45471MedDec 24, 2021
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

Page 9 of 21