Mediawiki

Mediawiki

371 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Published 10.01.2022 14:11:29
  • Last modified 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October.

  • EPSS 0.25%
  • Published 10.01.2022 14:11:28
  • Last modified 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll in...

  • EPSS 0.27%
  • Published 10.01.2022 14:11:28
  • Last modified 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.

  • EPSS 0.16%
  • Published 10.01.2022 14:11:27
  • Last modified 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.

  • EPSS 0.11%
  • Published 10.01.2022 14:11:27
  • Last modified 21.11.2024 06:33:41

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.

  • EPSS 0.31%
  • Published 24.12.2021 02:15:07
  • Last modified 21.11.2024 06:32:16

In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

  • EPSS 0.26%
  • Published 24.12.2021 02:15:07
  • Last modified 21.11.2024 06:32:16

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

Exploit
  • EPSS 0.33%
  • Published 24.12.2021 02:15:07
  • Last modified 21.11.2024 06:32:17

In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).

  • EPSS 0.26%
  • Published 24.12.2021 02:15:07
  • Last modified 21.11.2024 06:32:17

In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.

  • EPSS 0.27%
  • Published 20.12.2021 09:15:06
  • Last modified 21.11.2024 06:31:37

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one...