CVE-2023-45361
- EPSS 0.11%
- Published 09.10.2024 06:15:13
- Last modified 10.10.2024 12:51:56
An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it is not a valid title, leading to incorrect web pages...
CVE-2024-47913
- EPSS 0.15%
- Published 04.10.2024 22:15:02
- Last modified 17.06.2025 15:54:48
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to v...
CVE-2024-40596
- EPSS 0.11%
- Published 07.07.2024 00:15:10
- Last modified 18.03.2025 16:15:22
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)
CVE-2024-40597
- EPSS 0.28%
- Published 07.07.2024 00:15:10
- Last modified 17.06.2025 20:16:47
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.)
CVE-2024-40598
- EPSS 0.11%
- Published 07.07.2024 00:15:10
- Last modified 25.03.2025 17:15:59
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
CVE-2024-40599
- EPSS 0.09%
- Published 07.07.2024 00:15:10
- Last modified 20.03.2025 21:15:20
An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
CVE-2024-40600
- EPSS 0.09%
- Published 07.07.2024 00:15:10
- Last modified 21.11.2024 09:31:21
An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
CVE-2024-40601
- EPSS 0.07%
- Published 07.07.2024 00:15:10
- Last modified 21.11.2024 09:31:21
An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
CVE-2024-40602
- EPSS 0.09%
- Published 07.07.2024 00:15:10
- Last modified 14.03.2025 18:15:29
An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
CVE-2024-40603
- EPSS 0.06%
- Published 07.07.2024 00:15:10
- Last modified 17.03.2025 22:15:12
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.