Debian Mediawiki vulnerabilities
275 known vulnerabilities affecting debian/mediawiki.
Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6
Vulnerabilities
Page 4 of 14
CVE-2017-8815P4HIGHCVSS 7.5fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8815 [HIGH] CVE-2017-8815: mediawiki - The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.2...
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
Scope: local
bookworm: resolved (fixed in 1:1.27.4-1)
bullseye: resolved (fixed in 1:1.27.4-1)
forky: resolved (fixed in 1:1.27.4-1)
sid: resolved (fixed in 1:1.27.4-1)
trixie: resolved (fixed in 1:1.27.4-1)
debian
CVE-2025-32072P3MEDIUMCVSS 6.9fixed in mediawiki 1:1.39.13-1~deb12u1 (bookworm)2025
CVE-2025-32072 [MEDIUM] CVE-2025-32072: mediawiki - Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundatio...
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.
Scope: local
bookworm: resolved (fixed in 1:1.39.13-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u4)
forky: resolved (fixed in 1:1.43.1+dfsg-2)
s
debian
CVE-2019-12469P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12469 [MEDIUM] CVE-2019-12469: mediawiki - MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or lo...
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.2-1)
forky: resolved (fixed in 1:1.31.2-1)
sid: resolved (fixed in 1:1.31.2-1)
trixie: resolved (fixed in 1:1.31.2-
debian
CVE-2019-12470P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12470 [MEDIUM] CVE-2019-12470: mediawiki - Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log ...
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Scope: local
bookworm: resolved (fixed in 1:1.31.2-1)
bullseye: resolved (fixed in 1:1.31.2-1)
forky: resolved (fixed in 1:1.31.2-1)
sid: resolved (fixed in 1:1.31.2-1)
trixie: resolved (fixed in 1:1.31.2-
debian
CVE-2017-0362P4HIGHCVSS 8.8fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0362 [HIGH] CVE-2017-0362: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all p...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2017-8814P4HIGHCVSS 7.5fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8814 [HIGH] CVE-2017-8814: mediawiki - The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.2...
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
Scope: local
bookworm: resolved (fixed in 1:1.27.4-1)
bullseye: resolved (fixed in 1:1.27.4-1)
forky: resolved (fixed in 1:1.27.4-1)
sid: resolved (fixed in 1:1.27.4-1)
trixi
debian
CVE-2018-0505P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.31.1-1 (bookworm)2018
CVE-2018-0505 [MEDIUM] CVE-2018-0505: mediawiki - Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where Bo...
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
Scope: local
bookworm: resolved (fixed in 1:1.31.1-1)
bullseye: resolved (fixed in 1:1.31.1-1)
forky: resolved (fixed in 1:1.31.1-1)
sid: resolved (fixed in 1:1.31.1-1)
trixie: resolved (fixed in 1:1.31.1-1)
debian
CVE-2021-44857P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.35.5-1 (bookworm)2021
CVE-2021-44857 [MEDIUM] CVE-2021-44857: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1....
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit rights for). This applies to any public wiki, or a private wiki that has at least one page set in $wgWhitelistRead.
Sco
debian
CVE-2004-2186P4HIGHCVSS 7.5fixed in mediawiki 1.4.9 (bookworm)2004
CVE-2004-2186 [HIGH] CVE-2004-2186: mediawiki - SQL injection vulnerability in MediaWiki 1.3.5 allows remote attackers to execut...
SQL injection vulnerability in MediaWiki 1.3.5 allows remote attackers to execute arbitrary SQL commands via SpecialMaintenance.
Scope: local
bookworm: resolved (fixed in 1.4.9)
bullseye: resolved (fixed in 1.4.9)
forky: resolved (fixed in 1.4.9)
sid: resolved (fixed in 1.4.9)
trixie: resolved (fixed in 1.4.9)
debian
CVE-2024-34507P4HIGHCVSS 7.4fixed in mediawiki 1:1.39.7-1~deb12u1 (bookworm)2024
CVE-2024-34507 [HIGH] CVE-2024-34507: mediawiki - An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaW...
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
Scope: local
bookworm: resolved (fixed in 1:1.39.7-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in
debian
CVE-2018-0504P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.31.1-1 (bookworm)2018
CVE-2018-0504 [MEDIUM] CVE-2018-0504: mediawiki - Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information ...
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
Scope: local
bookworm: resolved (fixed in 1:1.31.1-1)
bullseye: resolved (fixed in 1:1.31.1-1)
forky: resolved (fixed in 1:1.31.1-1)
sid: resolved (fixed in 1:1.31.1-1)
trixie: resolved (fixed in 1:1.31.1-1)
debian
CVE-2023-45359P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-45359 [MEDIUM] CVE-2023-45359: mediawiki - An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5...
An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup.
Scope: local
bookworm: resolved (fixed in 1:1.39.5-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 1:1.39.5-1)
sid: resolved (fixed in 1:1.39.5-1)
debian
CVE-2015-2936P4HIGHCVSS 7.1fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2936 [HIGH] CVE-2015-2936: mediawiki - MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows r...
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1:1.19.20+dfsg-2.3)
forky: resolved (fixed in 1:1.19.20+dfsg-2.3)
sid: resolved (fixed in 1:1.19.20+dfsg-2.3)
tri
debian
CVE-2012-5391P4MEDIUMCVSS 6.8fixed in mediawiki 1:1.19.3-1 (bookworm)2012
CVE-2012-5391 [MEDIUM] CVE-2012-5391: mediawiki - Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, ...
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
Scope: local
bookworm: resolved (fixed in 1:1.19.3-1)
bullseye: resolved (fixed in 1:1.19.3-1)
forky: resolved (fixed in 1:1.19.3-1)
sid: resolved (fixed in 1:1.19.3-1)
tri
debian
CVE-2015-8003P4MEDIUMCVSS 6.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8003 [MEDIUM] CVE-2015-8003: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does no...
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
sid: resolved (fixed in 1:1.25.5-1
debian
CVE-2012-4379P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.19.2-1 (bookworm)2012
CVE-2012-4379 [MEDIUM] CVE-2012-4379: mediawiki - MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-...
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.
Scope: local
bookworm: resolved (fixed in 1:1.19.2-1)
bullseye: resolved (fixed in 1:1.19.2-1)
forky: resolved (fixed in 1:1.19.2-1)
sid: resolved
debian
CVE-2017-0369P4MEDIUMCVSS 6.5fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0369 [MEDIUM] CVE-2017-0369: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2013-2032P4LOWCVSS 5.0fixed in mediawiki 1:1.19.6-1 (bookworm)2013
CVE-2013-2032 [MEDIUM] CVE-2013-2032: mediawiki - MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to pr...
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
Scope: local
bookworm: resolved (fixed in 1:1.19.6-1)
bullseye: resolv
debian
CVE-2015-2937P4HIGHCVSS 7.1fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2937 [HIGH] CVE-2015-2937: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when usi...
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP, allows remote attackers to cause a denial of service ("quadratic blowup" and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, a different vulnerability than CVE-2015-2942.
Scope: local
debian
CVE-2019-19709P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.31.6-1 (bookworm)2019
CVE-2019-19709 [MEDIUM] CVE-2019-19709: mediawiki - MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protecti...
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Scope: local
bookworm: resolved (fixed in 1:1.31.6-1)
bullseye: resolved (fixed in 1:1.31.6-1)
forky: resol
debian