cbcvebase.

Debian Mediawiki vulnerabilities

275 known vulnerabilities affecting debian/mediawiki.

Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6

Vulnerabilities

Page 7 of 14
CVE-2020-25813P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.0-1 (bookworm)2020
CVE-2020-25813 [MEDIUM] CVE-2020-25813: mediawiki - In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:Use... In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users. Scope: local bookworm: resolved (fixed in 1:1.35.0-1) bullseye: resolved (fixed in 1:1.35.0-1) forky: resolved (fixed in 1:1.35.0-1) sid: resolved (fixed in 1:1.35.0-1) trixie: resolved (fixed in 1:1.35.0-1)
debian
CVE-2019-12467P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.31.2-1 (bookworm)2019
CVE-2019-12467 [MEDIUM] CVE-2019-12467: mediawiki - MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer ... MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. Scope: local bookworm: resolved (fixed in 1:1.31.2-1) bullseye: resolved (fixed in 1:1.31.2-1) forky: resolved (fixed in 1:1.31.2-1) sid: resolved
debian
CVE-2013-4302P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.19.8+dfsg-1 (bookworm)2013
CVE-2013-4302 [MEDIUM] CVE-2013-4302: mediawiki - (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (... (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow remote attackers to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism vi
debian
CVE-2020-10960P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.31.7-1 (bookworm)2020
CVE-2020-10960 [MEDIUM] CVE-2020-10960: mediawiki - In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) c... In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascading Style Sheets (CSS) selector. There is no known
debian
CVE-2022-41767P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.8-1 (bookworm)2022
CVE-2022-41767 [MEDIUM] CVE-2022-41767: mediawiki - An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.3... An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup. Scope: local bookworm: resolved (fixed in 1:1.35.8-1) bulls
debian
CVE-2021-44854P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.5-1 (bookworm)2021
CVE-2021-44854 [MEDIUM] CVE-2021-44854: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.... An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis. Scope: local bookworm: resolved (fixed in 1:1.35.5-1) bullseye: resolved (fixed in 1:1.35.8-1~deb11u1) forky: resolved (fixed in 1:1.35.5-1) sid: resolved (fixed in 1:1.35.5-1) trixie: resolved (fixed in 1:1
debian
CVE-2024-47913P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.39.10-1~deb12u1 (bookworm)2024
CVE-2024-47913 [MEDIUM] CVE-2024-47913: mediawiki - An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9... An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter. Scope: local bookworm: resolved (fixed in 1:1.39.10-1~deb12u1) bullseye: resol
debian
CVE-2012-4382P4MEDIUMCVSS 4.9fixed in mediawiki 1:1.19.2-1 (bookworm)2012
CVE-2012-4382 [MEDIUM] CVE-2012-4382: mediawiki - MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user... MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt. Scope: local bookworm: resolved (fixed in 1:1.19.2-1) bullseye: resolved (fixed in 1:1.19.2-1) forky: resolved (fixed in 1:1.19.2-1) sid: resolved (fixed in 1:1.19.2-1) trixie: resolv
debian
CVE-2026-34093P4UNKNOWNfixed in mediawiki 1:1.43.8+dfsg-1 (forky)2026
CVE-2026-34093 CVE-2026-34093: mediawiki bookworm: open bullseye: open forky: resolved (fixed in 1:1.43.8+dfsg-1) sid: resolved (fixed in 1:1.43.8+dfsg-1) trixie: open
debian
CVE-2025-6590P4MEDIUMCVSS 4.6fixed in mediawiki 1:1.39.13-1~deb12u1 (bookworm)2025
CVE-2025-6590 [MEDIUM] CVE-2025-6590: mediawiki - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiki... Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLUserTextField.Php. This issue affects MediaWiki: from * through 1.39.12, 1.42.76 1.43.1, 1.44.0. Scope: local bookworm: resolved (fixed in 1:1.39.13-1~deb12u1) bullseye: resolve
debian
CVE-2012-4378P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.19.2-1 (bookworm)2012
CVE-2012-4378 [MEDIUM] CVE-2012-4378: mediawiki - Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 a... Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php. Scope: local bookworm: resolved (fixed in 1:1.19.2-1) bullseye: resolved (fixed in 1:1.19.2-1) forky: resolved
debian
CVE-2015-8622P4LOWCVSS 6.1fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8622 [MEDIUM] CVE-2015-8622: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x bef... Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert('XSS!')." Scope: local bookworm: re
debian
CVE-2020-35478P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.1-1 (bookworm)2020
CVE-2020-35478 [MEDIUM] CVE-2020-35478: mediawiki - MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknam... MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later. Scope: local bookworm: resolved (fixed in 1:1.35.1-1) bullseye: resolved (fixed in 1:1.35.1-1) forky: resolved (fixed in 1:1.35.1-1) sid: resolved
debian
CVE-2021-41798P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.4-1 (bookworm)2021
CVE-2021-41798 [MEDIUM] CVE-2021-41798: mediawiki - MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not esc... MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page. Scope: local bookworm: resolved (fixed in 1:1.35.4-1) bullseye: resolved (fixed in 1:1.35.4-1~deb11u1) forky: resolved (fixed in 1:1.35.4-1) sid: resolved (fixed in 1:1.35.4-1) trixie: resolved (fixed in 1:1.35.4-1)
debian
CVE-2011-1579P4MEDIUMCVSS 5.8fixed in mediawiki 1:1.15.5-5 (bookworm)2011
CVE-2011-1579 [MEDIUM] CVE-2011-1579: mediawiki - The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaW... The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \2f\2a and \2a\2f hex strings to surround CSS comments. Scope: local bookw
debian
CVE-2022-28202P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.6-1 (bookworm)2022
CVE-2022-28202 [MEDIUM] CVE-2022-28202: mediawiki - An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, an... An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete. Scope: local bookworm: resolved (fixed in 1:1.35.6-1) bullseye: resolved (fixed in 1:1.35.8-1~deb11u1) forky: resolved (fixed
debian
CVE-2022-34912P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.7-1 (bookworm)2022
CVE-2022-34912 [MEDIUM] CVE-2022-34912: mediawiki - An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The... An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped. Scope: local bookworm: resolved (fixed in 1:1.35.7-1) bullseye: resolved (fixed in 1:1.35.8
debian
CVE-2022-34911P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.7-1 (bookworm)2022
CVE-2022-34911 [MEDIUM] CVE-2022-34911: mediawiki - An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.3... An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showS
debian
CVE-2023-51704P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.39.7-1~deb12u1 (bookworm)2023
CVE-2023-51704 [MEDIUM] CVE-2023-51704: mediawiki - An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x befor... An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights. Scope: local bookworm: resolved (fixed in 1:1.39.7-1~deb12u1) bullseye: resolved (fixed in 1:1.35.13-1+deb11u3) forky: resolved (fixed in 1
debian
CVE-2017-0368P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0368 [MEDIUM] CVE-2017-0368: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode a... Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages. Scope: local bookworm: resolved (fixed in 1:1.27.2-1) bullseye: resolved (fixed in 1:1.27.2-1) forky: resolved (fixed in 1:1.27.2-1) sid: resolved (fixed in 1:1.27.2-1) trixie: resolved (fixed in 1:1.27.2-1)
debian
Debian Mediawiki vulnerabilities | cvebase