cbcvebase.

Debian Mediawiki vulnerabilities

275 known vulnerabilities affecting debian/mediawiki.

Total CVEs
275
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW65UNKNOWN6

Vulnerabilities

Page 9 of 14
CVE-2025-67475P4UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-67475 [NONE] CVE-2025-67475: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/CommentFormatter/CommentParser.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1. Scope: local bookworm: resolved (fixed in 1:1.39.17
debian
CVE-2010-1190P4LOWCVSS 4.3fixed in mediawiki 1:1.15.2-1 (bookworm)2010
CVE-2010-1190 [MEDIUM] CVE-2010-1190: mediawiki - thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanis... thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations. Scope: local bookworm: resolved (fixed in 1:1.15.2-1) bullseye: resolved
debian
CVE-2025-61655P4UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-61655 [NONE] CVE-2025-61655: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated with program files includes/ApiVisualEditorEdit.Php, modules/ve-mw/init/targets/ve.Init.Mw.DesktopArticleTarget.Js, modules/ve-mw/ui/dialogs/ve.Ui.MWSaveDialog.Js. This issue affects Visual
debian
CVE-2017-0363P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0363 [MEDIUM] CVE-2017-0363: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?re... Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites. Scope: local bookworm: resolved (fixed in 1:1.27.2-1) bullseye: resolved (fixed in 1:1.27.2-1) forky: resolved (fixed in 1:1.27.2-1) sid: resolved (fixed in 1:1.27.2-1) trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2020-25812P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.35.0-1 (bookworm)2020
CVE-2020-25812 [MEDIUM] CVE-2020-25812: mediawiki - An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributi... An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML. Scope: local bookworm: resolved (fixed in 1:1.35.0-1) bullseye: resolved (fixed in 1:1.35.0-1) for
debian
CVE-2011-4360P4MEDIUMCVSS 5.0fixed in mediawiki 1:1.15.5-4 (bookworm)2011
CVE-2011-4360 [MEDIUM] CVE-2011-4360: mediawiki - MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all... MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter. Scope: local bookworm: resolved (fixed in 1:1.15.5-4) bullseye: resolved (fixed in 1:1.15.5-4) forky: resolved (fixed in 1:1.15.5-4) sid: resolved (fixed in 1:1.15.5-4) trixie: resolved (fixed in
debian
CVE-2010-1189P4LOWCVSS 5.0fixed in mediawiki 1:1.15.2-1 (bookworm)2010
CVE-2010-1189 [MEDIUM] CVE-2010-1189: mediawiki - MediaWiki before 1.15.2 does not prevent wiki editors from linking to images fro... MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue." Scope: local bookworm: resolved (fixed in 1:1.15.2-1) bullseye: resolved (fixed
debian
CVE-2021-30159P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.35.2-1 (bookworm)2021
CVE-2021-30159 [MEDIUM] CVE-2021-30159: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be... An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's only called if Title::getArticleID() returns non-zero with no special flags. Next, MovePage::moveToInternal() will d
debian
CVE-2025-11261P4UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-11261 [NONE] CVE-2025-11261: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Language/mediawiki.Language.Js. This issue affects MediaWiki: from * before 1.39.15, 1.43.5, 1.44.2. Scope: local bookworm: resolved (fixed in 1:1.39
debian
CVE-2025-67483P4LOWfixed in mediawiki 1:1.43.6+dfsg-1 (forky)2025
CVE-2025-67483 [NONE] CVE-2025-67483: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Page.Preview.Js. This issue affects MediaWiki: from * before 1.43.6, 1.44.3, 1.45.1. Scope: local bookworm: resolved bullseye: resolved forky: resolv
debian
CVE-2025-67477P4LOWfixed in mediawiki 1:1.43.6+dfsg-1 (forky)2025
CVE-2025-67477 [NONE] CVE-2025-67477: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js. This issue affects MediaWiki: from * before 1.44.3, 1.45.1. Scope: local bookworm: resolved bullseye: resolve
debian
CVE-2025-61656P4UNKNOWNfixed in mediawiki 1:1.39.17-1~deb12u1 (bookworm)2025
CVE-2025-61656 [NONE] CVE-2025-61656: mediawiki - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ... Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation VisualEditor. This vulnerability is associated with program files src/ce/ve.Ce.ClipboardHandler.Js. This issue affects VisualEditor: from * before 1.39.14, 1.43.4, 1.44.1. Scope: local bookworm: resolved (fixed in 1:1.39.17-1~deb12u1) b
debian
CVE-2017-8811P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8811 [MEDIUM] CVE-2017-8811: mediawiki - The implementation of raw message parameter expansion in MediaWiki before 1.27.4... The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks. Scope: local bookworm: resolved (fixed in 1:1.27.4-1) bullseye: resolved (fixed in 1:1.27.4-1) forky: resolved (fixed in 1:1.27.4-1) sid: resolved (fixed in 1:1.27.4-1) trixie: resolved (fixed in 1:1.27.4-1)
debian
CVE-2017-8808P4MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8808 [MEDIUM] CVE-2017-8808: mediawiki - MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS ... MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping. Scope: local bookworm: resolved (fixed in 1:1.27.4-1) bullseye: resolved (fixed in 1:1.27.4-1) forky: resolved (fixed in 1:1.27.4-1) sid: resolved (fixed in 1:1.27.4-1) trixie: resolved (
debian
CVE-2008-5252P4MEDIUMCVSS 5.8fixed in mediawiki 1:1.13.3-1 (bookworm)2008
CVE-2008-5252 [MEDIUM] CVE-2008-5252: mediawiki - Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in... Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x before 1.13.3 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors. Scope: local bookworm: resolved (fixed in 1:1.13.3-1) bullseye: resolved (fixed in 1:1.13.3-1) forky: resol
debian
CVE-2007-1055P4MEDIUMCVSS 5.1fixed in mediawiki 1.7.1-9 (bookworm)2007
CVE-2007-1055 [MEDIUM] CVE-2007-1055: mediawiki - Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in Me... Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter. NOTE: this issue might be a duplicate of CVE-2007-0177. Scope: local bookworm: resolved (fixed in 1.7.1-9) bullseye: resolved (fixed in 1.7.1-9) for
debian
CVE-2008-5687P4LOWCVSS 5.0fixed in mediawiki 1:1.13.3-1 (bookworm)2008
CVE-2008-5687 [MEDIUM] CVE-2008-5687: mediawiki - MediaWiki 1.11, and other versions before 1.13.3, does not properly protect agai... MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/. Scope: local bookworm: resolved (fixed in 1:1.13.3-1) bullseye: resolved (fixed in 1:1.13.3-1) forky: resolved (fixed in 1:1.13.3
debian
CVE-2012-4885P4LOWCVSS 5.0fixed in mediawiki 1:1.19.0-1 (bookworm)2012
CVE-2012-4885 [MEDIUM] CVE-2012-4885: mediawiki - The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 a... The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function. Scope: local bookworm: resolved (fixed in 1:1.19.0-1) bullseye: resolved (fixed in 1:1.19.0-1) forky: resolved (fixed in 1:1.19.0-1) sid: resolved (fixed in 1
debian
CVE-2014-2242P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.12+dfsg-1 (bookworm)2014
CVE-2014-2242 [MEDIUM] CVE-2014-2242: mediawiki - includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x be... includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an SVG upload, as demonstrated by use of a W3C XHTML namespace in conjunction with an IFRAME element. Scope: lo
debian
CVE-2015-2931P4MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2931 [MEDIUM] CVE-2015-2931: mediawiki - Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWik... Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an application/xml MIME type for a nested SVG with a data: URI. Scope: local bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3) bullseye: resolved (fixed in 1
debian
Debian Mediawiki vulnerabilities | cvebase