Mediawiki Core vulnerabilities
28 known vulnerabilities affecting mediawiki/core.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM20
Vulnerabilities
Page 1 of 2
CVE-2019-12468P3CRITICAL≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12468 [CRITICAL] CWE-284 Wikimedia MediaWiki Incorrect Access Control vulnerability
Wikimedia MediaWiki Incorrect Access Control vulnerability
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
ghsaosv
CVE-2023-45363P3HIGH≥ 0, < 1.35.12≥ 1.36.0, < 1.39.5+1 more2023-10-09
CVE-2023-45363 [HIGH] CWE-835 MediaWiki Denial of Service vulnerability
MediaWiki Denial of Service vulnerability
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
ghsaosv
CVE-2023-29141P3CRITICAL≥ 1.39.0, < 1.39.3≥ 1.38.0, < 1.38.6+1 more2023-03-31
CVE-2023-29141 [CRITICAL] CWE-444 X-Forwarded-For header allows brute-forcing autoblocked IP addresses
X-Forwarded-For header allows brute-forcing autoblocked IP addresses
An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
ghsaosv
CVE-2019-12472P3HIGH≥ 1.18.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12472 [HIGH] CWE-284 MediaWiki Incorrect Access Control vulnerability
MediaWiki Incorrect Access Control vulnerability
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2020-25827P3HIGH≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.32022-05-24
CVE-2020-25827 [HIGH] CWE-307 OATHAuth extension in MediaWiki is not implementing rate limit
OATHAuth extension in MediaWiki is not implementing rate limit
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
ghsaosv
CVE-2019-12474P3HIGH≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12474 [HIGH] CWE-200 Wikimedia information leak vulnerability
Wikimedia information leak vulnerability
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12473P3HIGH≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12473 [HIGH] CWE-400 Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple
Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12469P4MEDIUM≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12469 [MEDIUM] CWE-284 MediaWiki Incorrect Access Control vulnerability
MediaWiki Incorrect Access Control vulnerability
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12470P4MEDIUM≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12470 [MEDIUM] CWE-284 Wikimedia MediaWik exposed suppressed log in RevisionDelete page
Wikimedia MediaWik exposed suppressed log in RevisionDelete page
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2018-0505P4MEDIUM≥ 1.27.0, < 1.27.5≥ 1.29.0, < 1.29.3+2 more2022-05-13
CVE-2018-0505 [MEDIUM] CWE-287 Mediawiki BotPassword can bypass CentralAuth's account lock
Mediawiki BotPassword can bypass CentralAuth's account lock
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
ghsaosv
CVE-2018-0504P4MEDIUM≥ 1.27.0, < 1.27.5≥ 1.29.0, < 1.29.3+2 more2022-05-13
CVE-2018-0504 [MEDIUM] CWE-532 Mediawiki information disclosure vulnerability
Mediawiki information disclosure vulnerability
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
ghsaosv
CVE-2019-19709P4MEDIUM≥ 1.31.0, < 1.31.6≥ 1.32.0, < 1.32.6+2 more2022-05-24
CVE-2019-19709 [MEDIUM] CWE-601 Possible to circumvent title-blacklist
Possible to circumvent title-blacklist
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
ghsaosv
CVE-2021-41800P4MEDIUM≥ 0, < 1.36.22022-05-24
CVE-2021-41800 [MEDIUM] CWE-770 MediaWiki allows a denial of service
MediaWiki allows a denial of service
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
ghsaosv
CVE-2018-13258P4MEDIUM≥ 1.31.0, < 1.31.12022-05-14
CVE-2018-13258 [MEDIUM] CWE-284 Mediawiki tarball is missing .htaccess files
Mediawiki tarball is missing .htaccess files
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
ghsaosv
CVE-2020-25814P4MEDIUM≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.3+1 more2022-05-24
CVE-2020-25814 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS) vulnerability
MediaWiki Cross-site Scripting (XSS) vulnerability
In MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an tag (or it does not have a href attribute, or it's empty, etc.). The actual r
ghsaosv
CVE-2019-16738P4MEDIUM≥ 1.31.0, < 1.31.4≥ 1.32.0, < 1.32.4+1 more2022-05-24
CVE-2019-16738 [MEDIUM] CWE-200 MediaWiki information disclosure
MediaWiki information disclosure
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
ghsaosv
CVE-2020-10959P4MEDIUM≥ 0, < 1.34.0-rc.02022-05-24
CVE-2020-10959 [MEDIUM] CWE-601 MediaWiki Open Redirect vulnerability
MediaWiki Open Redirect vulnerability
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.34.0-rc.0 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
ghsaosv
CVE-2020-25813P4MEDIUM≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.32022-05-24
CVE-2020-25813 [MEDIUM] MediaWiki Special:UserRights exposes the existence of hidden users
MediaWiki Special:UserRights exposes the existence of hidden users
In MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3, Special:UserRights exposes the existence of hidden users.
ghsaosv
CVE-2019-12471P4MEDIUM≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+1 more2022-05-24
CVE-2019-12471 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS)
MediaWiki Cross-site Scripting (XSS)
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12467P4MEDIUM≥ 0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12467 [MEDIUM] CWE-284 MediaWiki Incorrect Access Control vulnerability
MediaWiki Incorrect Access Control vulnerability
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
1 / 2Next →