Debian Mediawiki vulnerabilities
275 known vulnerabilities affecting debian/mediawiki.
Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6
Vulnerabilities
Page 3 of 14
CVE-2026-34092P3UNKNOWNfixed in mediawiki 1:1.43.8+dfsg-1 (forky)2026
CVE-2026-34092 CVE-2026-34092: mediawiki
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
debian
CVE-2015-8624P3LOWCVSS 8.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8624 [HIGH] CVE-2015-8624: mediawiki - The User::matchEditToken function in includes/User.php in MediaWiki before 1.23....
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a
debian
CVE-2015-8623P3LOWCVSS 8.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8623 [HIGH] CVE-2015-8623: mediawiki - The User::matchEditToken function in includes/User.php in MediaWiki before 1.23....
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2020-36649P3LOWCVSS 3.5fixed in mediawiki 1:1.39.4-1~deb12u1 (bookworm)2020
CVE-2020-36649 [LOW] CVE-2020-36649: mediawiki - A vulnerability was found in mholt PapaParse up to 5.1.x. It has been classified...
A vulnerability was found in mholt PapaParse up to 5.1.x. It has been classified as problematic. Affected is an unknown function of the file papaparse.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 5.2.0 is able to address this issue. The name of the patch is 235a12758cd77266d2e98fd715f53536b34ad621. It is recommended
debian
CVE-2013-1817P3HIGHCVSS 7.5fixed in mediawiki 1:1.19.4-1 (bookworm)2013
CVE-2013-1817 [HIGH] CVE-2013-1817: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.ph...
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 1:1.19.4-1)
bullseye: resolved (fixed in 1:1.19.4-1)
forky: resolved (fixed in 1:1.19.4-1)
sid: resolved (fixed in 1:1.19.4-1)
trixie: resolved (fixed in 1:1.19.4-1)
debian
CVE-2019-12473P3HIGHCVSS 7.5fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12473 [HIGH] CVE-2019-12473: mediawiki - Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid title...
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.2-1)
forky: resolved (fixed in 1:1.31.2-1)
sid: resolved (fixed in 1:1.31.2-1)
tr
debian
CVE-2016-6332P3HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6332 [HIGH] CVE-2016-6332: mediawiki - MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $...
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in
debian
CVE-2021-44858P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.5-1 (bookworm)2021
CVE-2021-44858 [HIGH] CVE-2021-44858: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1....
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
Scope: local
bookworm: resolved (fixed in 1:1.35.5-1)
bullseye: resolved (fixed in 1:
debian
CVE-2024-34506P3HIGHCVSS 7.5fixed in mediawiki 1:1.39.7-1~deb12u1 (bookworm)2024
CVE-2024-34506 [HIGH] CVE-2024-34506: mediawiki - An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki be...
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.
Scope: local
bookw
debian
CVE-2026-34091P3LOWfixed in mediawiki 1:1.43.8+dfsg-1 (forky)2026
CVE-2026-34091 [LOW] CVE-2026-34091: mediawiki
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
debian
CVE-2026-34088P3UNKNOWNfixed in mediawiki 1:1.43.8+dfsg-1 (forky)2026
CVE-2026-34088 CVE-2026-34088: mediawiki
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
debian
CVE-2026-34087P3UNKNOWNfixed in mediawiki 1:1.43.8+dfsg-1 (forky)2026
CVE-2026-34087 CVE-2026-34087: mediawiki
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
debian
CVE-2021-20270P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-20270 [HIGH] CVE-2021-20270: mediawiki - An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denia...
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:1.35.2-1)
debian
CVE-2021-41799P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.4-1 (bookworm)2021
CVE-2021-41799 [HIGH] CVE-2021-41799: mediawiki - MediaWiki before 1.36.2 allows a denial of service (resource consumption because...
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.
Scope: local
bookworm: resolved (fixed in 1:1.35.4-1)
bullseye: resolved (fixed in 1:1.35.4-1~deb11u1)
forky: resolved (fixed in 1:1.35.4-1)
sid: resolved (fixed in 1:1.35.4
debian
CVE-2015-6728P3HIGHCVSS 7.5fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-6728 [HIGH] CVE-2015-6728: mediawiki - The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x befor...
The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection via a timing attack.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
debian
CVE-2013-1816P3HIGHCVSS 7.5fixed in mediawiki 1:1.19.4-1 (bookworm)2013
CVE-2013-1816 [HIGH] CVE-2013-1816: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to caus...
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Scope: local
bookworm: resolved (fixed in 1:1.19.4-1)
bullseye: resolved (fixed in 1:1.19.4-1)
forky: resolved (fixed in 1:1.19.4-1)
sid: resolved (fixed in 1:1.19.4-1)
trixie: resolved (fixed in 1:1.19.4-1
debian
CVE-2017-0361P3HIGHCVSS 7.8fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0361 [HIGH] CVE-2017-0361: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure fl...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2022-28203P3HIGHCVSS 7.5fixed in mediawiki 1:1.35.6-1 (bookworm)2022
CVE-2022-28203 [HIGH] CVE-2022-28203: mediawiki - A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x befo...
A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
Scope: local
bookworm: resolved (fixed in 1:1.35.6-1)
bullseye: resolved (fixed in 1:1.35.8-1~deb11u1)
forky: resolved (fixed in 1:
debian
CVE-2025-67480P3UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-67480 [NONE] CVE-2025-67480: mediawiki - Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryRevisionsBase.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.
Scope: local
bookworm: resolved (fixed in 1:1.39.17-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u6)
forky: resolved (fixed in 1:1.43.6+
debian
CVE-2016-6336P3MEDIUMCVSS 6.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6336 [MEDIUM] CVE-2016-6336: mediawiki - MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows ...
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion status of arbitrary file revisions by using Special:Undelete.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolv
debian