Vulnerability index

Browse CVEs

249 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mediawiki HIGH 7.5
CVE-2013-6453

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have un…

Fix: after 1.19.9
Fix from $1,950 2014-05-12
Mediawiki MEDIUM 5.0
CVE-2013-6472

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) l…

Fix: after 1.19.9
Fix from $1,600 2014-05-12
Mediawiki HIGH 7.5
CVE-2013-4571

Buffer overflow in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 has unspecifi…

Fix: after 1.19.9
Fix from $1,950 2014-05-12
Mediawiki MEDIUM 5.0
CVE-2013-4570

The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1…

Fix: after 1.19.9
Fix from $1,600 2014-05-12
Mediawiki MEDIUM 5.8
CVE-2014-2243

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon e…

Fix: after 1.19.11
Fix from $1,600 2014-03-02
Mediawiki MEDIUM 6.0
CVE-2014-1610EPSS 43%

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attac…

No fix yet
Fix from $1,600 2014-01-30
Mediawiki MEDIUM 6.8
CVE-2012-5394

Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.2…

Fix: after 1.19.8
Fix from $1,600 2013-12-13
Mediawiki MEDIUM 6.8
CVE-2013-2114

Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to e…

Patch available
Fix from $1,600 2013-11-18
Mediawiki MEDIUM 5.0
CVE-2013-4301

includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote att…

Patch available
Fix from $1,600 2013-10-27
Mediawiki MEDIUM 5.0
CVE-2013-4302

(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php…

Patch available
Fix from $1,600 2013-10-27
Mediawiki MEDIUM 6.8
CVE-2013-4306

Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3,…

Fix: 1.19.8 / 1.20.7+
Fix from $1,600 2013-10-11
Mediawiki MEDIUM 5.0
CVE-2012-4885

The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) v…

Mitigation only
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 6.8
CVE-2012-1580

Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers …

Mitigation only
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 5.0
CVE-2012-1579

The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which …

No fix yet
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 5.0
CVE-2012-1581

MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attacker…

Mitigation only
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 6.8
CVE-2012-1578

Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijac…

Mitigation only
Fix from $1,600 2012-09-09
Mediawiki MEDIUM 5.8
CVE-2011-1766

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth …

Fix: after 1.16.4
Fix from $1,600 2011-05-23
Mediawiki MEDIUM 5.8
CVE-2011-1579

The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (…

Fix: after 1.16.2
Fix from $1,600 2011-04-27
Mediawiki MEDIUM 6.8
CVE-2010-2789

PHP remote file inclusion vulnerability in MediaWikiParserTest.php in MediaWiki 1.16 beta, when register_globals is enabled, allows remote attackers …

Patch available
Fix from $1,600 2011-04-27
Mediawiki HIGH 7.5
CVE-2011-0537

Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions befo…

Patch available
Fix from $1,950 2011-02-04
Mediawiki MEDIUM 5.8
CVE-2011-0003

MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vect…

Fix: after 1.16.0
Fix from $1,600 2011-01-11
Mediawiki MEDIUM 6.8
CVE-2010-1648

Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote atta…

Patch available
Fix from $1,600 2010-06-08
Mediawiki MEDIUM 6.0
CVE-2010-1150

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes i…

Fix: after 1.15.2
Fix from $1,600 2010-04-20
Mediawiki MEDIUM 5.0
CVE-2010-1189

MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP ad…

Fix: after 1.15.1
Fix from $1,600 2010-03-31
Mediawiki MEDIUM 5.8
CVE-2008-5252

Cross-site request forgery (CSRF) vulnerability in the Special:Import feature in MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x bef…

Patch available
Fix from $1,600 2008-12-19
Mediawiki MEDIUM 5.0
CVE-2008-5687

MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remo…

Mitigation only
Fix from $1,600 2008-12-19
Mediawiki MEDIUM 5.0
CVE-2008-1318

Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback param…

Patch available
Fix from $1,600 2008-03-13
Mediawiki MEDIUM 6.8
CVE-2007-1054

Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remot…

Fix: after 1.8.2
Fix from $1,600 2007-02-21
Mediawiki MEDIUM 6.8
CVE-2007-1055

Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote at…

Fix: after 1.8.2
Fix from $1,600 2007-02-21
Mediawiki MEDIUM 5.0
CVE-2007-0894

MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3…

Patch available
Fix from $1,600 2007-02-12