Debian Mediawiki vulnerabilities
275 known vulnerabilities affecting debian/mediawiki.
Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6
Vulnerabilities
Page 2 of 14
CVE-2012-4380P3HIGHCVSS 7.5fixed in mediawiki 1:1.19.2-1 (bookworm)2012
CVE-2012-4380 [HIGH] CVE-2012-4380: mediawiki - MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to byp...
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:1.19.2-1)
bullseye: resolved (fixed in 1:1.19.2-1)
forky: resolved (fixed in 1:1.19.2-1)
sid: resolved (fixed in 1:1.19.2-1)
trixie: resolved (fixed
debian
CVE-2025-67478P3UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-67478 [NONE] CVE-2025-67478: mediawiki - Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associate...
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUser: from * before 1.39.14, 1.43.4, 1.44.1.
Scope: local
bookworm: resolved (fixed in 1:1.39.17-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u6)
forky: resolved (fixed in 1:1.43.6+dfsg-1)
sid: resol
debian
CVE-2007-0177P4MEDIUMCVSS 5.1PoCfixed in mediawiki 1.7.1-6 (bookworm)2007
CVE-2007-0177 [MEDIUM] CVE-2007-0177: mediawiki - Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before ...
Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.7.1-6)
bullseye: resolved (fixed in 1.7.1-6)
forky: resolve
debian
CVE-2016-6331P3HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6331 [HIGH] CVE-2016-6331: mediawiki - ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1....
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in 1:1.27.1-1)
sid: resolved (fixed in 1:1.27.1-1)
trixie: reso
debian
CVE-2017-0371P3HIGHCVSS 7.5fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0371 [HIGH] CVE-2017-0371: mediawiki - MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before...
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved
debian
CVE-2023-29141P3CRITICALCVSS 9.8fixed in mediawiki 1:1.39.4-1~deb12u1 (bookworm)2023
CVE-2023-29141 [CRITICAL] CVE-2023-29141: mediawiki - An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x befor...
An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
Scope: local
bookworm: resolved (fixed in 1:1.39.4-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.11-1~deb11u1)
forky: resolved (fixed in 1:1.39.4-1)
sid: resolved (fixed in 1:1.39.
debian
CVE-2013-4572P3HIGHCVSS 7.5fixed in mediawiki 1:1.19.8+dfsg-2.2 (bookworm)2013
CVE-2013-4572 [HIGH] CVE-2013-4572: mediawiki - The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, a...
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Scope: local
bookworm: resolved (fixed in 1:1.19.8+dfsg-2.2)
bullseye: resolved (fixed in 1:1.19.8+dfsg-2.2)
forky
debian
CVE-2021-35197P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.3-1 (bookworm)2021
CVE-2021-35197 [HIGH] CVE-2021-35197: mediawiki - In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x bef...
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
Scope: local
bookworm: resolved (fixed in 1:1.35.3-1)
bullseye: r
debian
CVE-2017-0367P3HIGHCVSS 8.8fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0367 [HIGH] CVE-2017-0367: mediawiki - Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, ...
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27
debian
CVE-2022-29248P3HIGHCVSS 8.0fixed in guzzle 7.4.4-1 (bookworm)2022
CVE-2022-29248 [HIGH] CVE-2022-29248: guzzle - Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a...
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled
debian
CVE-2019-12472P3HIGHCVSS 7.5fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12472 [HIGH] CVE-2019-12472: mediawiki - An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18....
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.2-1)
forky: resolved (fixed in 1:1.31.2-1
debian
CVE-2017-8810P3HIGHCVSS 7.5fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8810 [HIGH] CVE-2017-8810: mediawiki - MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a ...
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2014-9277P3HIGHCVSS 7.5fixed in mediawiki 1:1.19.20+dfsg-2.1 (bookworm)2014
CVE-2014-9277 [HIGH] CVE-2014-9277: mediawiki - The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.2...
The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing in a PHP format request, which causes the string length to change when converting the request to .
Scope: local
bookworm: reso
debian
CVE-2016-6337P3HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6337 [HIGH] CVE-2016-6337: mediawiki - MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended s...
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in 1:1.27.1-1)
sid: resolved (fixed in 1:1.27.1-1)
trix
debian
CVE-2021-27291P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-27291 [HIGH] CVE-2021-27291: mediawiki - In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages...
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: res
debian
CVE-2020-25827P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.0-1 (bookworm)2020
CVE-2020-25827 [HIGH] CVE-2020-25827: mediawiki - An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 an...
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
Scope: local
bookworm: resolved (fixe
debian
CVE-2019-12474P3HIGHCVSS 7.5fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12474 [HIGH] CVE-2019-12474: mediawiki - Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged AP...
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.2-1)
forky: resolved (fixed in 1:1.31.2-1)
sid: resolved (fi
debian
CVE-2016-6335P3HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6335 [HIGH] CVE-2016-6335: mediawiki - MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does no...
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in 1:1.27.1-1)
sid: re
debian
CVE-2020-35475P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.1-1 (bookworm)2020
CVE-2020-35475 [HIGH] CVE-2020-35475: mediawiki - In MediaWiki before 1.35.1, the messages userrights-expiry-current and userright...
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctl
debian
CVE-2013-6453P3HIGHCVSS 7.5fixed in mediawiki 1:1.19.10+dfsg-1 (bookworm)2013
CVE-2013-6453 [HIGH] CVE-2013-6453: mediawiki - MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not ...
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.
Scope: local
bookworm: resolved (fixed in 1:1.19.10+dfsg-1)
bullseye: resolved (fixed in 1:1.19.10+dfsg-1)
forky: resolved (fixed in 1:1.19.10+dfsg-1)
sid: resolved (fixed in 1:1.19.10+
debian