Vulnerability index

Browse CVEs

249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mediawiki MEDIUM 5.3
CVE-2021-45038

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can …

Fix: 1.35.5 / 1.36.3+
Fix from $1,600 2021-12-17
Mediawiki HIGH 8.8
CVE-2021-41801

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is …

Fix: 1.31.16 / 1.35.4+
Fix from $1,950 2021-10-11
Mediawiki HIGH 7.5
CVE-2021-42040

An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within…

Fix: after 1.36.2
Fix from $1,950 2021-10-06
Mediawiki MEDIUM 6.1
CVE-2021-42041

An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for…

Fix: after 1.36.2
Fix from $1,600 2021-10-06
Mediawiki MEDIUM 6.1
CVE-2021-42043

An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion text (a parameter to mediasea…

Fix: after 1.36.2
Fix from $1,600 2021-10-06
Mediawiki CRITICAL 9.8
CVE-2021-36126

An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the co…

Fix: after 1.36
Fix from $2,300 2021-07-02
Mediawiki CRITICAL 9.8
CVE-2021-36128

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly…

Fix: after 1.36
Fix from $2,300 2021-07-02
Mediawiki HIGH 8.8
CVE-2021-36132

An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRig…

Fix: after 1.36
Fix from $1,950 2021-07-02
Mediawiki HIGH 7.5
CVE-2021-36125

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops …

Fix: after 1.36
Fix from $1,950 2021-07-02
Mediawiki HIGH 7.5
CVE-2021-31555

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka oauth_registered_consumer.oarc…

Fix: after 1.35.2
Fix from $1,950 2021-04-22
Mediawiki MEDIUM 6.5
CVE-2021-31548

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blocked or was unsuccessfully bl…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 6.5
CVE-2021-31553

An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the …

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 6.1
CVE-2021-31551

An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related query parameters allowed for XSS …

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 5.4
CVE-2021-31550

An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a malicious actor could introd…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 5.4
CVE-2021-31552

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 5.4
CVE-2021-31554

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks for certain automatically cre…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki MEDIUM 5.3
CVE-2021-31545

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked the existence of certain delet…

Fix: after 1.35.2
Fix from $1,600 2021-04-22
Mediawiki HIGH 8.8
CVE-2020-29004

The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

Fix: after 1.35
Fix from $1,950 2021-01-29
Mediawiki HIGH 7.5
CVE-2020-29005

The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

Fix: after 1.35
Fix from $1,950 2021-01-29
Mediawiki HIGH 8.8
CVE-2020-35625

An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace c…

Fix: after 1.35.1
Fix from $1,950 2020-12-21
Mediawiki HIGH 8.8
CVE-2020-35626

An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefor…

Fix: after 1.35.1
Fix from $1,950 2020-12-21
Mediawiki HIGH 7.5
CVE-2020-35623

An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation wit…

Fix: after 1.35.1
Fix from $1,950 2020-12-21
Mediawiki MEDIUM 6.1
CVE-2020-35622

An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. Th…

Fix: after 1.35.1
Fix from $1,600 2020-12-21
Mediawiki MEDIUM 5.3
CVE-2020-35624

An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may p…

Fix: after 1.35.1
Fix from $1,600 2020-12-21
Mediawiki MEDIUM 5.4
CVE-2020-29003

The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Special:CreatePoll or Special:Upd…

Fix: after 1.35
Fix from $1,600 2020-11-24
Mediawiki MEDIUM 5.4
CVE-2020-27957

The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certain varieties of games were cr…

Fix: after 1.35
Fix from $1,600 2020-10-28
Skin\ MEDIUM 6.1
CVE-2020-27620

The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage …

Fix: after 1.35.0
Fix from $1,600 2020-10-22
Mediawiki MEDIUM 6.1
CVE-2020-10959

resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML cont…

Fix: 1.35+
Fix from $1,600 2020-06-02
Mediawiki HIGH 7.5
CVE-2020-12051

The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=…

Patch available
Fix from $1,950 2020-04-21
Mediawiki MEDIUM 5.3
CVE-2020-10960

In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user …

Fix: 1.34.1+
Fix from $1,600 2020-04-03