VYPR

ManageWiki

by MediaWiki

CVEs (4)

  • CVE-2025-43861Apr 24, 2025
    risk 0.00cvss epss 0.00

    ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the…

  • CVE-2025-32964Apr 22, 2025
    risk 0.00cvss epss 0.00

    ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting extension, a restricted extension would be automatically disabled even if the user did not hold the ManageWiki-restricted right. This issue has been patched…

  • CVE-2024-25109Feb 9, 2024
    risk 0.00cvss epss 0.00

    ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the form descriptor. An attacker may exploit this and would have a cross site scripting attack vector. Exploiting…

  • CVE-2021-29483Apr 28, 2021
    risk 0.00cvss epss 0.01

    ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageWiki variable to all users. This has been patched by https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patc…