cbcvebase.

Debian Mediawiki vulnerabilities

275 known vulnerabilities affecting debian/mediawiki.

Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6

Vulnerabilities

Page 6 of 14
CVE-2023-36674P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.39.4-1~deb12u1 (bookworm)2023
CVE-2023-36674 [MEDIUM] CVE-2023-36674: mediawiki - An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x befor... An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax. Scope: local bookworm: resolved (fixed in 1:1.39.4-1~deb12u1) bullseye: resolved (fixed in 1:1.35.11-
debian
CVE-2015-2940P4MEDIUMCVSS 6.8fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2940 [MEDIUM] CVE-2015-2940: mediawiki - Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for M... Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3) bullseye: resolved (fixed in 1:1.19.20+dfsg-2.3) forky: resolved (
debian
CVE-2014-5241P4MEDIUMCVSS 6.8fixed in mediawiki 1:1.19.18+dfsg-0.1 (bookworm)2014
CVE-2014-5241 [MEDIUM] CVE-2014-5241: mediawiki - The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18... The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a
debian
CVE-2013-1951P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.19.5-1 (bookworm)2013
CVE-2013-1951 [MEDIUM] CVE-2013-1951: mediawiki - A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x... A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. Scope: local bookworm: resolved (fixed in 1:1.19.5-1) bullseye: resolved (fixed in 1:1.19.5-1) forky: resolved (fixed in 1:1.19.5-1) sid: resolved (fixed in 1:1.19.5-1) trixie: res
debian
CVE-2012-4377P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.19.2-1 (bookworm)2012
CVE-2012-4377 [MEDIUM] CVE-2012-4377: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x b... Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary web script or HTML via a File: link to a nonexistent image. Scope: local bookworm: resolved (fixed in 1:1.19.2-1) bullseye: resolved (fixed in 1:1.19.2-1) forky: resolved (fixed in 1:1.19.2-1) sid: resolved (fixed in 1:1.19.2-1)
debian
CVE-2020-35479P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.1-1 (bookworm)2020
CVE-2020-35479 [MEDIUM] CVE-2020-35479: mediawiki - MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translat... MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later. Scope: local bookworm: resolved (fixed in 1:1.35.1-1) bullseye: resolved (fixed in 1:1.3
debian
CVE-2021-30157P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30157 [MEDIUM] CVE-2021-30157: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be... An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS. Scope: local bookworm: resolved (fixed in 1:1.35.2-1) bullseye: resolved (fixed in 1:1.35.2-1) fo
debian
CVE-2021-30154P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30154 [MEDIUM] CVE-2021-30154: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be... An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS. Scope: local bookworm: resolved (fixed in 1:1.35.2-1) bullseye: resolved (fixed in 1:1.35.2-1) forky: resolved (fixed in 1:1.35.2-1) sid: resolved (fixed in 1:1.3
debian
CVE-2019-12471P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12471 [MEDIUM] CVE-2019-12471: mediawiki - Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from ... Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. Scope: local bookworm: resolved (fixed in 1:1.31.2-1) bullseye: resolved (fixed in 1:1.31.2-1) forky: resolved (fixed in 1:1.31.2-1) s
debian
CVE-2020-25815P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.0-1 (bookworm)2020
CVE-2020-25815 [MEDIUM] CVE-2020-25815: mediawiki - An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEve... An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text(). Scope: local bookworm: resolved (fixed in 1:1.35.0-1) bullseye: resolved (fixed in 1:1.35.0-1) forky: resolved (fix
debian
CVE-2020-25828P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.0-1 (bookworm)2020
CVE-2020-25828 [MEDIUM] CVE-2020-25828: mediawiki - An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x be... An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (which can be based on user input). (When jqueryMsg is loaded, it correctly accepts only whitelisted tags in message co
debian
CVE-2010-1150P4LOWCVSS 6.0fixed in mediawiki 1:1.15.3-1 (bookworm)2010
CVE-2010-1150 [MEDIUM] CVE-2010-1150: mediawiki - MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle ... MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue. Scope: local bo
debian
CVE-2023-36675P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.39.4-1~deb12u1 (bookworm)2023
CVE-2023-36675 [MEDIUM] CVE-2023-36675: mediawiki - An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x befor... An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature. Scope: local bookworm: resolved (fixed in 1:1.39.4-1~deb12u1) bullseye: resolved (fixed in 1:1.35.11-1~deb11u1) forky: resolved (fixed in 1:1.39.4-1) sid: resolved
debian
CVE-2025-61646P4LOWCVSS 1.2fixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-61646 [LOW] CVE-2025-61646: mediawiki - Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associate... Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/RecentChanges/EnhancedChangesList.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1. Scope: local bookworm: resolved (fixed in 1:1.39.17-1~deb12u1) bullseye: resolved (fixed in 1:1.35.13-1+deb11u5) forky: resolved (fixed in 1:1.43.5+d
debian
CVE-2019-16738P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.31.4-1 (bookworm)2019
CVE-2019-16738 [MEDIUM] CVE-2019-16738: mediawiki - In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of s... In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup. Scope: local bookworm: resolved (fixed in 1:1.31.4-1) bullseye: resolved (fixed in 1:1.31.4-1) forky: resolved (fixed in 1:1.31.4-1) sid: resolved (fixed in 1:1.31.4-1) trixie: resolved (fixed in 1:1.31.4-1)
debian
CVE-2017-8812P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8812 [MEDIUM] CVE-2017-8812: mediawiki - MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows r... MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline. Scope: local bookworm: resolved (fixed in 1:1.27.4-1) bullseye: resolved (fixed in 1:1.27.4-1) forky: resolved (fixed in 1:1.27.4-1) sid: resolved (fixed in 1:1.27.4-1) trixie: resolved (fixed in
debian
CVE-2013-7444P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.25.5-1 (bookworm)2013
CVE-2013-7444 [MEDIUM] CVE-2013-7444: mediawiki - The Special:Contributions page in MediaWiki before 1.22.0 allows remote attacker... The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text. Scope: local bookworm: resolved (fixed in 1:1.25.5-1) bullseye: resolved (fixed in 1:1.25.5-1) forky: resolved (fixed in 1:1.25.5-1) sid: resolved (fixed in 1:1.25.5-1) trixie: resolved (fixed in 1:1.25.5-1)
debian
CVE-2020-35477P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.1-1 (bookworm)2020
CVE-2020-35477 [MEDIUM] CVE-2020-35477: mediawiki - MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some s... MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysubmit (instead
debian
CVE-2015-8628P4LOWCVSS 5.3fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8628 [MEDIUM] CVE-2015-8628: mediawiki - The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Spe... The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics. Scope: local book
debian
CVE-2021-45038P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.5-1 (bookworm)2021
CVE-2021-45038 [MEDIUM] CVE-2021-45038: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.... An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents. Scope: local bookworm: resolved (fixed in 1:1.35.5-1) bullseye: resolved (fixed in 1:1.35.4-1+deb11u2) forky: resolved (fixed in 1:1.35.5-1) sid: resolved (fixed in 1:1.35.5-1) trixie: re
debian
Debian Mediawiki vulnerabilities | cvebase