Mediawiki

Mediawiki

371 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Published 07.07.2024 00:15:10
  • Last modified 18.03.2025 19:15:43

An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries.

Exploit
  • EPSS 0.07%
  • Published 07.07.2024 00:15:10
  • Last modified 14.03.2025 14:15:16

An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.

  • EPSS 0.3%
  • Published 05.05.2024 19:15:07
  • Last modified 11.06.2025 14:44:14

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to ...

  • EPSS 0.16%
  • Published 05.05.2024 19:15:07
  • Last modified 17.06.2025 14:53:28

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST...

Exploit
  • EPSS 0.15%
  • Published 05.05.2024 19:15:07
  • Last modified 17.06.2025 16:40:07

An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands...

Exploit
  • EPSS 0.4%
  • Published 05.05.2024 19:15:07
  • Last modified 17.06.2025 16:37:39

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1...

  • EPSS 0.23%
  • Published 27.03.2024 06:15:08
  • Last modified 21.11.2024 07:56:36

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.

Exploit
  • EPSS 0.39%
  • Published 12.01.2024 06:15:47
  • Last modified 03.06.2025 14:15:46

An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.

Exploit
  • EPSS 0.35%
  • Published 12.01.2024 06:15:47
  • Last modified 03.06.2025 14:15:46

An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

Exploit
  • EPSS 0.36%
  • Published 12.01.2024 06:15:47
  • Last modified 21.11.2024 08:57:07

An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.