Mediawiki

Mediawiki

395 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 12.05.2014 14:55:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to videos.

  • EPSS 0.45%
  • Veröffentlicht 29.04.2014 18:55:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.

  • EPSS 0.2%
  • Veröffentlicht 20.04.2014 01:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authe...

  • EPSS 0.5%
  • Veröffentlicht 02.03.2014 04:57:25
  • Zuletzt bearbeitet 29.04.2026 01:13:23

includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks...

  • EPSS 0.38%
  • Veröffentlicht 02.03.2014 04:57:25
  • Zuletzt bearbeitet 29.04.2026 01:13:23

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain acces...

  • EPSS 0.46%
  • Veröffentlicht 02.03.2014 04:57:25
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTM...

  • EPSS 48.04%
  • Veröffentlicht 30.01.2014 23:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/med...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 26.01.2014 20:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote att...

  • EPSS 0.46%
  • Veröffentlicht 13.12.2013 18:07:54
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS.

  • EPSS 0.5%
  • Veröffentlicht 13.12.2013 18:07:54
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as dem...