Vulnerability index

Browse CVEs

249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Abusefilter HIGH 7.5
CVE-2019-16528

An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive informa…

Patch available
Fix from $1,950 2020-03-20
Checkuser MEDIUM 5.3
CVE-2019-16529

An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in…

Fix: after 1.35
Fix from $1,600 2020-03-19
Mobilefrontend MEDIUM 6.1
CVE-2019-15124

In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL…

No fix yet
Fix from $1,600 2020-03-19
Mediawiki CRITICAL 9.8
CVE-2020-10534

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-…

Fix: after 1.34.0
Fix from $2,300 2020-03-12
Mediawiki HIGH 8.1
CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attacke…

Fix: 1.18.5 / 1.19.2+
Fix from $1,950 2020-02-08
Mediawiki MEDIUM 6.1
CVE-2013-6451

Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to …

Fix: 1.19.10 / 1.21.4+
Fix from $1,600 2020-01-28
Mediawiki MEDIUM 5.3
CVE-2013-6455

The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via …

Fix: 1.19.10 / 1.21.4+
Fix from $1,600 2020-01-28
Mediawiki MEDIUM 5.9
CVE-2014-9481

The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted mod…

Fix: 1.19.23 / 1.22.15+
Fix from $1,600 2020-01-27
Mediawiki MEDIUM 6.1
CVE-2020-6163

The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in t…

Patch available
Fix from $1,600 2020-01-08
Mediawiki MEDIUM 6.1
CVE-2019-19910

The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouse…

Patch available
Fix from $1,600 2019-12-19
Mediawiki MEDIUM 6.1
CVE-2013-4303

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not prop…

Fix: 1.19.8 / 1.20.7+
Fix from $1,600 2019-12-11
Visual Editor MEDIUM 6.1
CVE-2019-19708

The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.

Fix: after 1.34
Fix from $1,600 2019-12-11
Abusefilter MEDIUM 5.3
CVE-2019-18987

An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been ma…

Fix: after 1.34
Fix from $1,600 2019-11-15
Checkuser MEDIUM 6.5
CVE-2019-18611

An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made a…

Fix: after 1.34
Fix from $1,600 2019-10-29
Abusefilter MEDIUM 5.3
CVE-2019-18612

An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or…

Fix: after 1.34
Fix from $1,600 2019-10-29
Mediawiki HIGH 7.5
CVE-2012-0046

mediawiki allows deleted text to be exposed

Fix: 1.17.2 / 1.18.1+
Fix from $1,950 2019-10-29
Mobilefrontend MEDIUM 6.1
CVE-2019-14807

In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.…

Fix: after 1.33.0
Fix from $1,600 2019-08-09
Mediawiki HIGH 7.5
CVE-2019-12472

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blo…

Fix: 1.27.6 / 1.30.2+
Fix from $1,950 2019-07-10
Mediawiki MEDIUM 5.3
CVE-2018-13258

Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.

Fix: after 1.31.1
Fix from $1,600 2018-10-04
Mediawiki MEDIUM 5.3
CVE-2014-1686

MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.

No fix yet
Fix from $1,600 2018-04-16
Mediawiki MEDIUM 6.1
CVE-2012-4377

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary web script o…

Fix: after 1.18.4
Fix from $1,600 2017-10-26
Mediawiki MEDIUM 6.1
CVE-2012-4378

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used…

Fix: after 1.18.4
Fix from $1,600 2017-10-26
Mediawiki HIGH 7.5
CVE-2012-4380

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an accoun…

Fix: after 1.18.4
Fix from $1,950 2017-10-19
Mediawiki MEDIUM 6.5
CVE-2012-4379

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct c…

Fix: after 1.18.4
Fix from $1,600 2017-10-19
Mediawiki CRITICAL 9.8
CVE-2014-9487

The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service…

Mitigation only
Fix from $2,300 2017-10-17
Mediawiki CRITICAL 9.8
CVE-2015-8009

The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not …

Fix: after 1.23.10
Fix from $2,300 2017-07-25
Mediawiki HIGH 7.5
CVE-2016-6331

ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restri…

Fix: after 1.23.14
Fix from $1,950 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6332

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain …

Fix: after 1.23.14
Fix from $1,950 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6335

MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows r…

Fix: after 1.23.14
Fix from $1,950 2017-04-20
Mediawiki HIGH 7.5
CVE-2016-6337

MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights …

Patch available
Fix from $1,950 2017-04-20