Debian Mediawiki vulnerabilities
304 known vulnerabilities affecting debian/mediawiki.
Total CVEs
304
CISA KEV
0
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH47MEDIUM133LOW94UNKNOWN6
Vulnerabilities
Page 9 of 16
CVE-2017-0363MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0363 [MEDIUM] CVE-2017-0363: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?re...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2017-8812MEDIUMCVSS 5.3fixed in mediawiki 1:1.27.4-1 (bookworm)2017
CVE-2017-8812 [MEDIUM] CVE-2017-8812: mediawiki - MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows r...
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
Scope: local
bookworm: resolved (fixed in 1:1.27.4-1)
bullseye: resolved (fixed in 1:1.27.4-1)
forky: resolved (fixed in 1:1.27.4-1)
sid: resolved (fixed in 1:1.27.4-1)
trixie: resolved (fixed in
debian
CVE-2017-0370MEDIUMCVSS 5.3fixed in mediawiki 1:1.27.2-1 (bookworm)2017
CVE-2017-0370 [MEDIUM] CVE-2017-0370: mediawiki - Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist i...
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
debian
CVE-2016-6337HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6337 [HIGH] CVE-2016-6337: mediawiki - MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended s...
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in 1:1.27.1-1)
sid: resolved (fixed in 1:1.27.1-1)
trix
debian
CVE-2016-6331HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6331 [HIGH] CVE-2016-6331: mediawiki - ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1....
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in 1:1.27.1-1)
sid: resolved (fixed in 1:1.27.1-1)
trixie: reso
debian
CVE-2016-6335HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6335 [HIGH] CVE-2016-6335: mediawiki - MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does no...
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in 1:1.27.1-1)
sid: re
debian
CVE-2016-6332HIGHCVSS 7.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6332 [HIGH] CVE-2016-6332: mediawiki - MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $...
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
forky: resolved (fixed in
debian
CVE-2016-6336MEDIUMCVSS 6.5fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6336 [MEDIUM] CVE-2016-6336: mediawiki - MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows ...
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion status of arbitrary file revisions by using Special:Undelete.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolv
debian
CVE-2016-6334MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6334 [MEDIUM] CVE-2016-6334: mediawiki - Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 me...
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullse
debian
CVE-2016-6333MEDIUMCVSS 6.1fixed in mediawiki 1:1.27.1-1 (bookworm)2016
CVE-2016-6333 [MEDIUM] CVE-2016-6333: mediawiki - Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature...
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.
Scope: local
bookworm: resolved (fixed in 1:1.27.1-1)
bullseye: resolved (fixed in 1:1.27.1-1)
fork
debian
CVE-2015-2937HIGHCVSS 7.1fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2937 [HIGH] CVE-2015-2937: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when usi...
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP, allows remote attackers to cause a denial of service ("quadratic blowup" and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, a different vulnerability than CVE-2015-2942.
Scope: local
debian
CVE-2015-6728HIGHCVSS 7.5fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-6728 [HIGH] CVE-2015-6728: mediawiki - The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x befor...
The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection via a timing attack.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
debian
CVE-2015-2936HIGHCVSS 7.1fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2936 [HIGH] CVE-2015-2936: mediawiki - MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows r...
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1:1.19.20+dfsg-2.3)
forky: resolved (fixed in 1:1.19.20+dfsg-2.3)
sid: resolved (fixed in 1:1.19.20+dfsg-2.3)
tri
debian
CVE-2015-2935MEDIUMCVSS 5.0fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2935 [MEDIUM] CVE-2015-2935: mediawiki - MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows re...
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1:1.19.20+dfsg-2.3)
fork
debian
CVE-2015-2931MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2931 [MEDIUM] CVE-2015-2931: mediawiki - Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWik...
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an application/xml MIME type for a nested SVG with a data: URI.
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1
debian
CVE-2015-8002MEDIUMCVSS 6.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8002 [MEDIUM] CVE-2015-8002: mediawiki - The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1....
The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
debian
CVE-2015-8005MEDIUMCVSS 5.0fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8005 [MEDIUM] CVE-2015-8005: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses th...
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.
debian
CVE-2015-2938MEDIUMCVSS 4.3fixed in mediawiki 1:1.19.20+dfsg-2.3 (bookworm)2015
CVE-2015-2938 [MEDIUM] CVE-2015-2938: mediawiki - Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x befor...
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a custom JavaScript file, which is not properly handled when previewing the file.
Scope: local
bookworm: resolved (fixed in 1:1.19.20+dfsg-2.3)
bullseye: resolved (fixed in 1:1.19.20+d
debian
CVE-2015-6730MEDIUMCVSS 4.3fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-6730 [MEDIUM] CVE-2015-6730: mediawiki - Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.1...
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter, which is not properly handled in an error page, related to "ForeignAPI images."
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved
debian
CVE-2015-8003MEDIUMCVSS 6.8fixed in mediawiki 1:1.25.5-1 (bookworm)2015
CVE-2015-8003 [MEDIUM] CVE-2015-8003: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does no...
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file uploads, which allows remote authenticated users to have unspecified impact via multiple file uploads.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
sid: resolved (fixed in 1:1.25.5-1
debian