Debian Mediawiki vulnerabilities
275 known vulnerabilities affecting debian/mediawiki.
Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6
Vulnerabilities
Page 1 of 14
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCfixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-11358 [MEDIUM] CVE-2019-11358: mediawiki - jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishan...
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.
debian
CVE-2014-1610P2MEDIUMCVSS 6.0PoCfixed in mediawiki 1:1.19.11+dfsg-1 (bookworm)2014
CVE-2014-1610 [MEDIUM] CVE-2014-1610: mediawiki - MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11,...
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/Pdf
debian
CVE-2017-0372P2CRITICALCVSS 9.8PoCfixed in mediawiki 1:1.27.3-1 (bookworm)2017
CVE-2017-0372 [CRITICAL] CVE-2017-0372: mediawiki - Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.1...
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
Scope: local
bookworm: resolved (fixed in 1:1.27.3-1)
bullseye: resolved (fixed in 1:1.27.3-1)
forky: resolved (fixed in 1:1.27.3-1)
sid: resolved (fixed in 1:1.27.3-1)
trixie: resolved (fixed in 1:1.27.3-1)
debian
CVE-2004-1405P3HIGHCVSS 7.5PoCfixed in mediawiki 1.4.9 (bookworm)2004
CVE-2004-1405 [HIGH] CVE-2004-1405: mediawiki - MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly h...
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 1.4.9)
bullseye: resolved (fixed in 1.4.9)
forky: resolved (fixed in 1.4.9)
sid: resolved (fixed in 1.4.9)
trixie: resolve
debian
CVE-2019-12468P3CRITICALCVSS 9.8fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12468 [CRITICAL] CVE-2019-12468: mediawiki - An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27....
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.2-1)
forky: resolved (fixed in 1:1.31.2-1)
sid:
debian
CVE-2025-67484P3UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-67484 [NONE] CVE-2025-67484: mediawiki - Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
Scope: local
bookworm: resolved (fixed in 1:1.39.17-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u6)
forky: resolved (fixed in 1:1.43.6+dfsg-1)
s
debian
CVE-2017-8809P3CRITICALCVSS 9.8fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8809 [CRITICAL] CVE-2017-8809: mediawiki - api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29...
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
Scope: local
bookworm: resolved (fixed in 1:1.27.4-1)
bullseye: resolved (fixed in 1:1.27.4-1)
forky: resolved (fixed in 1:1.27.4-1)
sid: resolved (fixed in 1:1.27.4-1)
trixie: resolved (fixed in 1:1.27.4-1)
debian
CVE-2023-45363P3HIGHCVSS 7.5fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-45363 [HIGH] CVE-2023-45363: mediawiki - An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x th...
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Scope: local
bookworm: resolved (fixed in 1:1.39.5-
debian
CVE-2025-11175P3LOWCVSS 8.8fixed in mediawiki 1:1.43.5+dfsg-1 (forky)2025
CVE-2025-11175 [HIGH] CVE-2025-11175: mediawiki - Improper Neutralization of Special Elements used in an Expression Language State...
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki - DiscussionTools Extension: 1.44, 1.43.
Scope: local
bookworm: resolved
bullseye: resolved
f
debian
CVE-2025-6926P3HIGHCVSS 8.8fixed in mediawiki 1:1.39.13-1~deb12u1 (bookworm)2025
CVE-2025-6926 [HIGH] CVE-2025-6926: mediawiki - Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - Centra...
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Scope: local
bookworm: resolved (fixed in 1:1.39.13-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+d
debian
CVE-2015-8626P3LOWCVSS 9.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8626 [CRITICAL] CVE-2015-8626: mediawiki - The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.2...
The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to obtain access via a brute-force attack.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.
debian
CVE-2023-3550P3HIGHCVSS 7.3fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-3550 [HIGH] CVE-2023-3550: mediawiki - Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if...
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
Scope: local
bookworm: resolved (fixed in 1:1.39.5-1~deb12u1)
bullseye: reso
debian
CVE-2012-4381P3HIGHCVSS 8.1fixed in mediawiki 1:1.19.2-1 (bookworm)2012
CVE-2012-4381 [HIGH] CVE-2012-4381: mediawiki - MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local d...
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an e
debian
CVE-2021-41801P3HIGHCVSS 8.8fixed in mediawiki 1:1.35.4-1 (bookworm)2021
CVE-2021-41801 [HIGH] CVE-2021-41801: mediawiki - The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Contro...
The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)
Scope: local
bookworm: resolved (fixed in 1:1.35.4-1)
bullseye: resolved (fixed in 1:1.35.4-1~deb11u1)
forky: resolved (fixed in 1:1.35.4
debian
CVE-2022-31090P3HIGHCVSS 7.7fixed in guzzle 7.4.5-1 (bookworm)2022
CVE-2022-31090 [HIGH] CVE-2022-31090: guzzle - Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are s...
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or port), if we cho
debian
CVE-2012-2698P4MEDIUMCVSS 4.3PoCfixed in mediawiki 1:1.19.1-1 (bookworm)2012
CVE-2012-2698 [MEDIUM] CVE-2012-2698: mediawiki - Cross-site scripting (XSS) vulnerability in the outputPage function in includes/...
Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.
Scope: local
bookworm: resolved (fixed in 1:1.19.1-1)
bullseye: resolved (fixed i
debian
CVE-2022-31043P3HIGHCVSS 7.5fixed in guzzle 7.4.4-1 (bookworm)2022
CVE-2022-31043 [HIGH] CVE-2022-31043: guzzle - Guzzle is an open source PHP HTTP client. In affected versions `Authorization` h...
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we should not forward the `Authorization` header on. This is much the same as to how we don't forward on the header if the
debian
CVE-2013-2114P3MEDIUMCVSS 6.8fixed in mediawiki 1:1.19.7+dfsg-1 (bookworm)2013
CVE-2013-2114 [MEDIUM] CVE-2013-2114: mediawiki - Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19...
Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
Scope: local
bookworm: resolved (fixed in 1:1.19.7+dfsg-1)
bullseye: resolved (fixed in 1:1.19.7+dfsg-1)
forky: resolved (fixed in 1:1.19.7+dfsg-
debian
CVE-2022-31091P3HIGHCVSS 7.7fixed in guzzle 7.4.5-1 (bookworm)2022
CVE-2022-31091 [HIGH] CVE-2022-31091: guzzle - Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on r...
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we choose to follow it, we should remove the `Authorization` and `Cookie` headers from the request, before containing. Previously, we would only co
debian
CVE-2022-31042P3HIGHCVSS 7.5fixed in guzzle 7.4.4-1 (bookworm)2022
CVE-2022-31042 [HIGH] CVE-2022-31042: guzzle - Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` head...
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on making a request to a server which responds with a redirect to a a URI to a different host, we should not forward the `
debian
1 / 14Next →