Debian Mediawiki vulnerabilities
275 known vulnerabilities affecting debian/mediawiki.
Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6
Vulnerabilities
Page 10 of 14
CVE-2007-1054P4MEDIUMCVSS 6.8fixed in mediawiki 1.7.1-9 (bookworm)2007
CVE-2007-1054 [MEDIUM] CVE-2007-1054: mediawiki - Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in Me...
Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer.
Scope: local
bookworm: resolved (fixed in 1.7.1-9)
bullseye: resolved (fixed i
debian
CVE-2015-2932P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2932 [MEDIUM] CVE-2015-2932: mediawiki - Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23...
Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink element.
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1:1.19.20+dfsg-2.3)
forky: resolved (fixed in 1:1.19.20+dfsg-2.3)
s
debian
CVE-2015-2934P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2934 [MEDIUM] CVE-2015-2934: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not ...
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1:1.19.20+dfsg-
debian
CVE-2021-30152P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30152 [MEDIUM] CVE-2021-30152: mediawiki - An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x be...
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:1.
debian
CVE-2021-30155P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30155 [MEDIUM] CVE-2021-30155: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be...
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:1.35.2-1)
sid: resolv
debian
CVE-2021-30153P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30153 [MEDIUM] CVE-2021-30153: mediawiki - An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.1...
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.
Scope: local
bo
debian
CVE-2004-2185P4MEDIUMCVSS 6.8fixed in mediawiki 1.4.9 (bookworm)2004
CVE-2004-2185 [MEDIUM] CVE-2004-2185: mediawiki - Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow rem...
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow remote attackers to execute arbitrary scripts and/or SQL queries via (1) the UnicodeConverter extension, (2) raw page views, (3) SpecialIpblocklist, (4) SpecialEmailuser, (5) SpecialMaintenance, and (6) ImagePage.
Scope: local
bookworm: resolved (fixed in 1.4.9)
bullseye: resolved (fixed
debian
CVE-2017-0365P4MEDIUMCVSS 4.7fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0365 [MEDIUM] CVE-2017-0365: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in Searc...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2014-5243P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.18+dfsg-0.1 (bookworm)2014
CVE-2014-5243 [MEDIUM] CVE-2014-5243: mediawiki - MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before...
MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Scope: local
bookworm: resolved (fixed in 1:1.19.18+dfsg-0.1)
bullseye: resolved (fixed in 1:1.19.18+dfsg-0.
debian
CVE-2010-2787P4LOWCVSS 4.3fixed in mediawiki 1:1.15.5-1 (bookworm)2010
CVE-2010-2787 [MEDIUM] CVE-2010-2787: mediawiki - api.php in MediaWiki before 1.15.5 does not prevent use of public caching header...
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-1)
bullseye: resolved (fixed in
debian
CVE-2025-6595P4UNKNOWNfixed in mediawiki 1:1.39.13-1~deb12u1 (bookworm)2025
CVE-2025-6595 [NONE] CVE-2025-6595: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.
Scope: local
bookworm: resolved (fixed in 1:1.39.13-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u4)
forky: resolved (fixed i
debian
CVE-2025-6594P4UNKNOWNfixed in mediawiki 1:1.39.13-1~deb12u1 (bookworm)2025
CVE-2025-6594 [NONE] CVE-2025-6594: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandbox.Js. This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.
Scope: local
bookworm: resolved (fix
debian
CVE-2015-8004P4MEDIUMCVSS 4.0fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8004 [MEDIUM] CVE-2015-8004: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does no...
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not properly restrict access to revisions, which allows remote authenticated users with the viewsuppressed user right to remove revision suppressions via a crafted revisiondelete action, which returns a valid a change form.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye:
debian
CVE-2023-45362P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-45362 [MEDIUM] CVE-2023-45362: mediawiki - An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.3...
An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak.
Scope: local
bookworm: resolved (fixed in 1:1.39.5-1~deb12u1)
bullseye: resolved (fix
debian
CVE-2011-1580P4LOWCVSS 3.5fixed in mediawiki 1:1.15.5-5 (bookworm)2011
CVE-2011-1580 [LOW] CVE-2011-1580: mediawiki - The transwiki import functionality in MediaWiki before 1.16.3 does not properly ...
The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-5)
bullseye: resolved (fixed in 1:1.15.5-5)
forky: resolved (fixed in 1:1.15.5-5)
sid: resolved (fixed
debian
CVE-2025-61639P4LOWCVSS 1.7fixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-61639 [LOW] CVE-2025-61639: mediawiki - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki...
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/ManualLogEntry.Php, includes/recentchanges/RecentChangeFactory.Php, includes/recentchanges/RecentChangeStore.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
Scope:
debian
CVE-2013-4301P4LOWCVSS 5.0fixed in mediawiki 1:1.19.8+dfsg-1 (bookworm)2013
CVE-2013-4301 [MEDIUM] CVE-2013-4301: mediawiki - includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.1...
includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to obtain sensitive information via a "<" (open angle bracket) character in the lang parameter to w/load.php, which reveals the installation path in an error message.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2008-1318P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.11.2-1 (bookworm)2008
CVE-2008-1318 [MEDIUM] CVE-2008-1318: mediawiki - Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attacker...
Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback parameter in an API call for JavaScript Object Notation (JSON) formatted results.
Scope: local
bookworm: resolved (fixed in 1:1.11.2-1)
bullseye: resolved (fixed in 1:1.11.2-1)
forky: resolved (fixed in 1:1.11.2-1)
sid: re
debian
CVE-2012-1582P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.15.5-9 (bookworm)2012
CVE-2012-1582 [MEDIUM] CVE-2012-1582: mediawiki - Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.1...
Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-9)
bullseye: resolved (fixed
debian
CVE-2011-0047P4LOWCVSS 4.3fixed in mediawiki 1:1.15.5-3 (bookworm)2011
CVE-2011-0047 [MEDIUM] CVE-2011-0047: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remot...
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."
Scope: local
bookworm: resolved (fixed in 1:1.15.5-3)
bullseye: resolved (fixed in 1:1.15.5-3)
forky: resolved (fixed in 1:1.15.5-3)
sid: resolved (f
debian