Debian Mediawiki vulnerabilities
275 known vulnerabilities affecting debian/mediawiki.
Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6
Vulnerabilities
Page 5 of 14
CVE-2013-4303P4LOWCVSS 6.1fixed in mediawiki 1:1.19.8+dfsg-1 (bookworm)2013
CVE-2013-4303 [MEDIUM] CVE-2013-4303: mediawiki - includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before...
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wi
debian
CVE-2025-61641P4LOWCVSS 1.7fixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-61641 [LOW] CVE-2025-61641: mediawiki - Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
Scope: local
bookworm: resolved (fixed in 1:1.39.17-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u5)
forky: resolved (fixed in 1:1.43.5+dfsg-1)
sid: r
debian
CVE-2015-8002P4MEDIUMCVSS 6.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8002 [MEDIUM] CVE-2015-8002: mediawiki - The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1....
The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
debian
CVE-2021-41800P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.4-1 (bookworm)2021
CVE-2021-41800 [MEDIUM] CVE-2021-41800: mediawiki - MediaWiki before 1.36.2 allows a denial of service (resource consumption because...
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
Scope: local
bookworm: resolved (fixed in 1:1.35.4-1)
bullseye: resolved (fixed in 1:1.35.4-1~deb11u1)
forky: resolved (fi
debian
CVE-2021-30158P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30158 [MEDIUM] CVE-2021-30158: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be...
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unaut
debian
CVE-2015-8627P4LOWCVSS 5.3fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8627 [MEDIUM] CVE-2015-8627: mediawiki - MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x...
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero-padded octets, which might allow remote attackers to bypass intended access restrictions by using an IP address that was not supposed to have been allowed.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullse
debian
CVE-2015-2942P4LOWCVSS 7.1fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2942 [HIGH] CVE-2015-2942: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when usi...
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an (1) SVG file or (2) XMP metadata in a PDF file, aka a "billion laughs attack," a different vulnerability than CVE-2015-2937.
Scope: local
bookwo
debian
CVE-2012-1581P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.15.5-9 (bookworm)2012
CVE-2012-1581 [MEDIUM] CVE-2012-1581: mediawiki - MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers...
MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
Scope: local
bookworm: resolved (fixed in 1:1.15.5-9)
bullseye: resolved (fixed in 1:1.15.5-9)
forky: resolved (fixed in 1:1.15.5-9)
sid: resolved (fixed in 1:1.15.5-9)
tr
debian
CVE-2010-1648P4LOWCVSS 6.8fixed in mediawiki 1:1.15.4-1 (bookworm)2010
CVE-2010-1648 [MEDIUM] CVE-2010-1648: mediawiki - Cross-site request forgery (CSRF) vulnerability in the login interface in MediaW...
Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for requests that (1) create accounts or (2) reset passwords, related to the Special:Userlogin form.
Scope: local
bookworm: resolved (fixed in 1:1.15.4-1)
bullseye: resolved
debian
CVE-2021-30458P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30458 [MEDIUM] CVE-2021-30458: mediawiki - An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.1...
An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a tag, bypassing sanitization steps, and potentially allowing for XSS.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:
debian
CVE-2014-2243P4MEDIUMCVSS 5.8fixed in mediawiki 1:1.19.12+dfsg-1 (bookworm)2014
CVE-2014-2243 [MEDIUM] CVE-2014-2243: mediawiki - includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, ...
includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.
Scope: local
b
debian
CVE-2020-35480P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.1-1 (bookworm)2020
CVE-2020-35480 [MEDIUM] CVE-2020-35480: mediawiki - An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that...
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.
Scope: lo
debian
CVE-2025-61643P4LOWCVSS 2.7fixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-61643 [LOW] CVE-2025-61643: mediawiki - Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate...
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1.
Scope: local
bookworm: resolved (fixed in 1:1.39.17-1~deb12u1)
bullseye: resolved (fixed in 1:1.35.13-1+deb11u5)
forky: resolved (fixed in 1:1
debian
CVE-2026-34095P4UNKNOWNfixed in mediawiki 1:1.43.8+dfsg-2 (sid)2026
CVE-2026-34095 CVE-2026-34095: mediawiki
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 1:1.43.8+dfsg-2)
trixie: open
debian
CVE-2020-25814P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.0-1 (bookworm)2020
CVE-2020-25814 [MEDIUM] CVE-2020-25814: mediawiki - In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related...
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an tag (or it does not have a href attribute, or it's empty, etc.). The actua
debian
CVE-2023-45361P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-45361 [MEDIUM] CVE-2023-45361: mediawiki - An issue was discovered in VectorComponentUserLinks.php in the Vector Skin compo...
An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it is not a valid title, leading to incorrect web pages.
Scope: local
bookworm: resolved (fixed in 1:1.39.5-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 1:1.3
debian
CVE-2017-0366P4MEDIUMCVSS 5.4fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0366 [MEDIUM] CVE-2017-0366: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2015-6727P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-6727 [MEDIUM] CVE-2015-6727: mediawiki - The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before...
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
sid: resolved (fixed in 1:1.2
debian
CVE-2017-0370P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0370 [MEDIUM] CVE-2017-0370: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist i...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2005-0535P4HIGHCVSS 7.5fixed in mediawiki 1.4.9 (bookworm)2005
CVE-2005-0535 [HIGH] CVE-2005-0535: mediawiki - Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11...
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
Scope: local
bookworm: resolved (fixed in 1.4.9)
bullseye: resolved (fixed in 1.4.9)
forky: resolved (fixed in 1.4.9)
sid: resolved (fixed in 1.4.9)
trixie: resolved (fi
debian