cbcvebase.

Debian Mediawiki vulnerabilities

275 known vulnerabilities affecting debian/mediawiki.

Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6

Vulnerabilities

Page 8 of 14
CVE-2005-0536P4MEDIUMCVSS 5.0fixed in mediawiki 1.4.9 (bookworm)2005
CVE-2005-0536 [MEDIUM] CVE-2005-0536: mediawiki - Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta ... Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion. Scope: local bookworm: resolved (fixed in 1.4.9) bullseye: resolved (fixed in 1.4.9) forky: resolved (fixed in 1.4.9) sid: resolved (fixed in 1.4.9) t
debian
CVE-2023-45360P4MEDIUMCVSS 5.4fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-45360 [MEDIUM] CVE-2023-45360: mediawiki - An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x befor... An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers. Scope: local bookworm: resolved (fixed in 1:1.39.5-1~deb12u1) bullseye: resolved (fixed in 1:1.35.13-1~deb11
debian
CVE-2021-44855P4MEDIUMCVSS 5.4fixed in mediawiki 1:1.35.5-1 (bookworm)2021
CVE-2021-44855 [MEDIUM] CVE-2021-44855: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.... An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature. Scope: local bookworm: resolved (fixed in 1:1.35.5-1) bullseye: resolved (fixed in 1:1.35.8-1~deb11u1) forky: resolved (fixed in 1:1.35.5-1) sid: resolved (fixed in 1:1.35.5-1) trixie: resolved (fixe
debian
CVE-2013-6472P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.19.10+dfsg-1 (bookworm)2013
CVE-2013-6472 [MEDIUM] CVE-2013-6472: mediawiki - MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows re... MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) log API, (2) enhanced RecentChanges, and (3) user watchlists. Scope: local bookworm: resolved (fixed in 1:1.19.10+dfsg-1) bullseye: resolved (fixed in 1:1.19.10+dfsg-1) forky: resolved (fixed in 1:1.19.10+dfsg-1) sid:
debian
CVE-2023-45364P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.39.5-1~deb12u1 (bookworm)2023
CVE-2023-45364 [MEDIUM] CVE-2023-45364: mediawiki - An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through... An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information. Scope:
debian
CVE-2008-0460P4LOWCVSS 4.3fixed in mediawiki 1:1.11.1-1 (bookworm)2008
CVE-2008-0460 [MEDIUM] CVE-2008-0460: mediawiki - Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 throug... Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in
debian
CVE-2025-61642P4LOWfixed in mediawiki 1:1.43.5+dfsg-1 (forky)2025
CVE-2025-61642 [NONE] CVE-2025-61642: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/CodexHTMLForm.Php, includes/htmlform/fields/HTMLButtonField.Php. This issue affects MediaWiki: from * before 1.39.14, 1.43.4, 1.44.1. Scope: local bookworm
debian
CVE-2011-0003P4MEDIUMCVSS 5.8fixed in mediawiki 1:1.15.5-2 (bookworm)2011
CVE-2011-0003 [MEDIUM] CVE-2011-0003: mediawiki - MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows ... MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:1.15.5-2) bullseye: resolved (fixed in 1:1.15.5-2) forky: resolved (fixed in 1:1.15.5-2) sid: resolved (fixed in 1:1.15.5-2) trixie: resolved (fixed in 1:1.15.5-2)
debian
CVE-2016-6334P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6334 [MEDIUM] CVE-2016-6334: mediawiki - Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 me... Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links. Scope: local bookworm: resolved (fixed in 1:1.27.1-1) bullse
debian
CVE-2017-0364P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0364 [MEDIUM] CVE-2017-0364: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search ... Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link. Scope: local bookworm: resolved (fixed in 1:1.27.2-1) bullseye: resolved (fixed in 1:1.27.2-1) forky: resolved (fixed in 1:1.27.2-1) sid: resolved (fixed in 1:1.27.2-1) trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2013-6451P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.19.10+dfsg-1 (bookworm)2013
CVE-2013-6451 [MEDIUM] CVE-2013-6451: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2... Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values. Scope: local bookworm: resolved (fixed in 1:1.19.10+dfsg-1) bullseye: resolved (fixed in 1:1.19.10+dfsg-1) forky: resolved (fixed in 1:1.19.10+dfsg-1) si
debian
CVE-2020-35474P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.1-1 (bookworm)2020
CVE-2020-35474 [MEDIUM] CVE-2020-35474: mediawiki - In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::tex... In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML. Scope: local bookworm: resolved (fixed in 1:1.35.1-1) bullseye: resolved (fixed in 1:1.35.1-1) forky: resolved (fixed in 1:1.35.1-1) sid: reso
debian
CVE-2016-6333P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6333 [MEDIUM] CVE-2016-6333: mediawiki - Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature... Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css. Scope: local bookworm: resolved (fixed in 1:1.27.1-1) bullseye: resolved (fixed in 1:1.27.1-1) fork
debian
CVE-2011-4361P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.15.5-4 (bookworm)2011
CVE-2011-4361 [MEDIUM] CVE-2011-4361: mediawiki - MediaWiki before 1.17.1 does not check for read permission before handling actio... MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions. Scope: local bookworm: resolve
debian
CVE-2015-2935P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2935 [MEDIUM] CVE-2015-2935: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows re... MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT." Scope: local bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3) bullseye: resolved (fixed in 1:1.19.20+dfsg-2.3) fork
debian
CVE-2022-47927P4MEDIUMCVSS 5.5fixed in mediawiki 1:1.39.1-1 (bookworm)2022
CVE-2022-47927 [MEDIUM] CVE-2022-47927: mediawiki - An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before... An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data. Scope: local bookworm: resolved (fixed in 1:1.
debian
CVE-2015-8005P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8005 [MEDIUM] CVE-2015-8005: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses th... MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file. Scope: local bookworm: resolved (fixed in 1:1.25.5-1) bullseye: resolved (fixed in 1:1.25.5-1) forky: resolved (fixed in 1:1.25.
debian
CVE-2022-41765P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.8-1 (bookworm)2022
CVE-2022-41765 [MEDIUM] CVE-2022-41765: mediawiki - An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.3... An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users. Scope: local bookworm: resolved (fixed in 1:1.35.8-1) bullseye: resolved (fixed in 1:1.35.8-1~deb11u1) forky: resolved (fixed in 1:1.35.8-1) sid: resolved (fixed in 1:1.35.8-1) trixie: resolved (f
debian
CVE-2021-44856P4MEDIUMCVSS 5.3fixed in mediawiki 1:1.35.5-1 (bookworm)2021
CVE-2021-44856 [MEDIUM] CVE-2021-44856: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.... An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of the EditFilterMergedContent hook return value. Scope: local bookworm: resolved (fixed in 1:1.35.5-1) bullseye: resolved (fixed in 1:1.35.8-1~deb11u1) forky: reso
debian
CVE-2025-67481P4UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-67481 [NONE] CVE-2025-67481: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.JqueryMsg/mediawiki.JqueryMsg.Js. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1. Scope: local bookworm: resolved (fixed
debian
Debian Mediawiki vulnerabilities | cvebase