cbcvebase.

Mediawiki Core vulnerabilities

28 known vulnerabilities affecting mediawiki/core.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM20

Vulnerabilities

Page 1 of 2
CVE-2019-12468P3CRITICAL≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12468 [CRITICAL] CWE-284 Wikimedia MediaWiki Incorrect Access Control vulnerability Wikimedia MediaWiki Incorrect Access Control vulnerability An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
ghsaosv
CVE-2023-45363P3HIGH≥ 0, < 1.35.12≥ 1.36.0, < 1.39.5+1 more2023-10-09
CVE-2023-45363 [HIGH] CWE-835 MediaWiki Denial of Service vulnerability MediaWiki Denial of Service vulnerability An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
ghsaosv
CVE-2023-29141P3CRITICAL≥ 1.39.0, < 1.39.3≥ 1.38.0, < 1.38.6+1 more2023-03-31
CVE-2023-29141 [CRITICAL] CWE-444 X-Forwarded-For header allows brute-forcing autoblocked IP addresses X-Forwarded-For header allows brute-forcing autoblocked IP addresses An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
ghsaosv
CVE-2019-12472P3HIGH≥ 1.18.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12472 [HIGH] CWE-284 MediaWiki Incorrect Access Control vulnerability MediaWiki Incorrect Access Control vulnerability An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2020-25827P3HIGH≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.32022-05-24
CVE-2020-25827 [HIGH] CWE-307 OATHAuth extension in MediaWiki is not implementing rate limit OATHAuth extension in MediaWiki is not implementing rate limit An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
ghsaosv
CVE-2019-12474P3HIGH≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12474 [HIGH] CWE-200 Wikimedia information leak vulnerability Wikimedia information leak vulnerability Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12473P3HIGH≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12473 [HIGH] CWE-400 Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12469P4MEDIUM≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12469 [MEDIUM] CWE-284 MediaWiki Incorrect Access Control vulnerability MediaWiki Incorrect Access Control vulnerability MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12470P4MEDIUM≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12470 [MEDIUM] CWE-284 Wikimedia MediaWik exposed suppressed log in RevisionDelete page Wikimedia MediaWik exposed suppressed log in RevisionDelete page Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2018-0505P4MEDIUM≥ 1.27.0, < 1.27.5≥ 1.29.0, < 1.29.3+2 more2022-05-13
CVE-2018-0505 [MEDIUM] CWE-287 Mediawiki BotPassword can bypass CentralAuth's account lock Mediawiki BotPassword can bypass CentralAuth's account lock Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
ghsaosv
CVE-2018-0504P4MEDIUM≥ 1.27.0, < 1.27.5≥ 1.29.0, < 1.29.3+2 more2022-05-13
CVE-2018-0504 [MEDIUM] CWE-532 Mediawiki information disclosure vulnerability Mediawiki information disclosure vulnerability Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
ghsaosv
CVE-2019-19709P4MEDIUM≥ 1.31.0, < 1.31.6≥ 1.32.0, < 1.32.6+2 more2022-05-24
CVE-2019-19709 [MEDIUM] CWE-601 Possible to circumvent title-blacklist Possible to circumvent title-blacklist MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
ghsaosv
CVE-2021-41800P4MEDIUM≥ 0, < 1.36.22022-05-24
CVE-2021-41800 [MEDIUM] CWE-770 MediaWiki allows a denial of service MediaWiki allows a denial of service MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
ghsaosv
CVE-2018-13258P4MEDIUM≥ 1.31.0, < 1.31.12022-05-14
CVE-2018-13258 [MEDIUM] CWE-284 Mediawiki tarball is missing .htaccess files Mediawiki tarball is missing .htaccess files Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
ghsaosv
CVE-2020-25814P4MEDIUM≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.3+1 more2022-05-24
CVE-2020-25814 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS) vulnerability MediaWiki Cross-site Scripting (XSS) vulnerability In MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an tag (or it does not have a href attribute, or it's empty, etc.). The actual r
ghsaosv
CVE-2019-16738P4MEDIUM≥ 1.31.0, < 1.31.4≥ 1.32.0, < 1.32.4+1 more2022-05-24
CVE-2019-16738 [MEDIUM] CWE-200 MediaWiki information disclosure MediaWiki information disclosure In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
ghsaosv
CVE-2020-10959P4MEDIUM≥ 0, < 1.34.0-rc.02022-05-24
CVE-2020-10959 [MEDIUM] CWE-601 MediaWiki Open Redirect vulnerability MediaWiki Open Redirect vulnerability resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.34.0-rc.0 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
ghsaosv
CVE-2020-25813P4MEDIUM≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.32022-05-24
CVE-2020-25813 [MEDIUM] MediaWiki Special:UserRights exposes the existence of hidden users MediaWiki Special:UserRights exposes the existence of hidden users In MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3, Special:UserRights exposes the existence of hidden users.
ghsaosv
CVE-2019-12471P4MEDIUM≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+1 more2022-05-24
CVE-2019-12471 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS) MediaWiki Cross-site Scripting (XSS) Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
CVE-2019-12467P4MEDIUM≥ 0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12467 [MEDIUM] CWE-284 MediaWiki Incorrect Access Control vulnerability MediaWiki Incorrect Access Control vulnerability MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ghsaosv
Mediawiki Core vulnerabilities | cvebase