VYPR

Vendor CVEs

MediaWiki

All CVEs

512 total · sorted by risk
  • CVE-2026-58029MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php,…

  • CVE-2026-58027MedJul 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

  • CVE-2026-39837MedApr 7, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

  • CVE-2025-61646MedFeb 3, 2026
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.

  • CVE-2025-7363MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject…

  • CVE-2025-7362MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The vulnerability occurs in the file upload UI when the same filename is uploaded twice. This issue affects…

  • CVE-2025-53479MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to inject JavaScript through the uselang=x-xss language override mechanism. This…

  • CVE-2025-53480MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit this by appending ?uselang=x-xss to the URL, causing reflected XSS when…

  • CVE-2025-53478MedJul 7, 2025
    risk 0.35cvss 5.4epss 0.00

    The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension: from 1.39.X…

  • CVE-2025-53487MedJul 7, 2025
    risk 0.35cvss 5.4epss 0.00

    The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are inserted into raw HTML without proper escaping. Attackers can exploit this by injecting JavaScript payloads via the uselang=x-xss language override, which causes…

  • CVE-2025-53486MedJul 7, 2025
    risk 0.35cvss 5.4epss 0.00

    The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly concatenated into inline HTML without escaping. An attacker can inject JavaScript event handlers such as onmouseenter using carefully crafted input via the…

  • CVE-2024-47816MedOct 9, 2024
    risk 0.35cvss 6.4epss 0.00

    ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the central wiki, the user on the…

  • CVE-2024-23178MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

  • CVE-2024-23174MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter-date-range-format-placeh…

  • CVE-2024-23172MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog.

  • CVE-2024-23171MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows XSS via the x-xss language setting for internationalization (i18n).

  • CVE-2023-45360MedNov 3, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.

  • CVE-2023-37304MedJun 30, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature.

  • CVE-2023-37300MedJun 30, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.

  • CVE-2023-22910MedJan 20, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have…

  • CVE-2023-22909MedJan 10, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.

  • CVE-2022-41767MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions…

  • CVE-2022-41765MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.

  • CVE-2021-44855MedDec 26, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

  • CVE-2021-42047MedSep 29, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-mentee-overview-no-js-fallba…

  • CVE-2021-42045MedSep 29, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to create alerts by changing their User-Agent HTTP header and submitting a vote.

  • CVE-2021-46146MedJan 10, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.

  • CVE-2021-45471MedDec 24, 2021
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

  • CVE-2021-45038MedDec 17, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

  • CVE-2021-31554MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically created MediaWiki user accounts, thus allowing nefarious users to remain unblocked.

  • CVE-2021-31552MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create…

  • CVE-2021-31550MedApr 22, 2021
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a malicious actor could introduce XSS payloads into various layers.

  • CVE-2021-31545MedApr 22, 2021
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain deleted MediaWiki usernames, related to rev_deleted.

  • CVE-2021-30158MedApr 6, 2021
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been…

  • CVE-2020-35624MedDec 21, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.

  • CVE-2020-35480MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about…

  • CVE-2020-35477MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.02

    MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox)…

  • CVE-2020-29003MedNov 24, 2020
    risk 0.35cvss 5.4epss 0.01

    The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Special:CreatePoll or Special:UpdatePoll.

  • CVE-2020-27957MedOct 28, 2020
    risk 0.35cvss 5.4epss 0.01

    The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were created within MediaWiki, their names or titles could be manipulated to generate stored XSS within the RandomGameUnit extension.

  • CVE-2020-25813MedSep 27, 2020
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.

  • CVE-2020-10960MedApr 3, 2020
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows…

  • CVE-2019-16529MedMar 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.

  • CVE-2020-9382MedFeb 24, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

  • CVE-2013-6455MedJan 28, 2020
    risk 0.35cvss 5.3epss 0.01

    The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

  • CVE-2019-18987MedNov 15, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's…

  • CVE-2019-18612MedOct 29, 2019
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.

  • CVE-2019-12467MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.01

    MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2018-13258MedOct 4, 2018
    risk 0.35cvss 5.3epss 0.02

    Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.

  • CVE-2014-1686MedApr 16, 2018
    risk 0.35cvss 5.3epss 0.02

    MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.

  • CVE-2017-0370MedApr 13, 2018
    risk 0.35cvss 5.3epss 0.01

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.

Page 5 of 11