cbcvebase.

Mediawiki Core vulnerabilities

28 known vulnerabilities affecting mediawiki/core.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM20

Vulnerabilities

Page 2 of 2
CVE-2020-10960P4MEDIUM≥ 1.31.0, < 1.31.7≥ 1.33.0, < 1.33.3+1 more2022-05-24
CVE-2020-10960 [MEDIUM] CWE-116 MediaWiki makeCollapsible allows applying event handler to any CSS selector MediaWiki makeCollapsible allows applying event handler to any CSS selector In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascadi
ghsaosv
CVE-2020-25815P4MEDIUM≥ 1.32.0, < 1.34.3≥ 1.35.0-rc.0, < 1.35.02022-05-24
CVE-2020-25815 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS) vulnerability MediaWiki Cross-site Scripting (XSS) vulnerability An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
ghsaosv
CVE-2020-25828P4MEDIUM≥ 1.31.0, < 1.31.9≥ 1.32.0, < 1.34.3+1 more2022-05-24
CVE-2020-25828 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS) vulnerability MediaWiki Cross-site Scripting (XSS) vulnerability An issue was discovered in MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (which can be based on user input). (When jqueryMsg is loaded, it correctly accepts only whitelisted tags in message conte
ghsaosv
CVE-2020-25812P4MEDIUM≥ 1.34.0, < 1.34.3≥ 1.35.0-rc.0, < 1.35.02022-05-24
CVE-2020-25812 [MEDIUM] CWE-79 MediaWiki Cross-site Scripting (XSS) vulnerability MediaWiki Cross-site Scripting (XSS) vulnerability An issue was discovered in MediaWiki 1.34.x before 1.34.3. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
ghsaosv
CVE-2014-2853P4MEDIUM≥ 0, < 1.21.9≥ 1.22.0, < 1.22.62022-05-17
CVE-2014-2853 [MEDIUM] CWE-79 Cross-site scripting vulnerability in includes/actions/InfoAction.php Cross-site scripting vulnerability in includes/actions/InfoAction.php Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.
ghsaosv
CVE-2018-0503P4MEDIUM≥ 1.27.0, < 1.27.5≥ 1.29.0, < 1.29.3+2 more2022-05-13
CVE-2018-0503 [MEDIUM] CWE-269 Mediawiki Improper Privilege Management Mediawiki Improper Privilege Management Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
ghsaosv
CVE-2020-15005P4MEDIUM≥ 0, < 1.31.8≥ 1.32.0, < 1.33.4+1 more2022-05-24
CVE-2020-15005 [MEDIUM] CWE-200 img_auth.php may leak private extension images into the public cache img_auth.php may leak private extension images into the public cache In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mish
ghsaosv
CVE-2019-12466HIGH≥ 1.27.0, < 1.27.6≥ 1.30.0, < 1.30.2+2 more2022-05-24
CVE-2019-12466 [HIGH] CWE-352 Wikimedia MediaWiki allows CSRF Wikimedia MediaWiki allows CSRF Wikimedia MediaWiki through 1.32.1 allows CSRF in logout feature.
ghsaosv
Mediawiki Core vulnerabilities | cvebase