CVE-2024-47781
- EPSS 0.81%
- Veröffentlicht 07.10.2024 22:15:03
- Zuletzt bearbeitet 14.11.2024 18:19:28
CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displayed in the request wiki queue when requesting a wik...
CVE-2024-34701
- EPSS 0.38%
- Veröffentlicht 14.05.2024 15:39:28
- Zuletzt bearbeitet 21.11.2024 09:19:13
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requeste...
CVE-2024-29897
- EPSS 0.06%
- Veröffentlicht 28.03.2024 14:15:14
- Zuletzt bearbeitet 21.11.2024 09:08:34
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm to access suppressed wiki requests by going to the request's entry on Special:RequestWi...
CVE-2024-29898
- EPSS 0.17%
- Veröffentlicht 28.03.2024 14:15:14
- Zuletzt bearbeitet 08.01.2026 18:53:33
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki requests to private wikis that added Special:RequestWikiQueue to the read w...
CVE-2024-29883
- EPSS 0.27%
- Veröffentlicht 26.03.2024 14:15:09
- Zuletzt bearbeitet 02.01.2026 13:37:07
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those with the `(createwiki)` user right regardless of the settings one sets on a...
CVE-2022-24813
- EPSS 0.23%
- Veröffentlicht 04.04.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:09
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this issue is available in the `mas...