Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2019-16528
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive informa…
Abusefilter
Patch available
MEDIUM 5.3
CVE-2019-16529
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in…
Checkuser
after 1.35
MEDIUM 6.1
CVE-2019-15124
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL…
Mobilefrontend
No fix yet
CRITICAL 9.8
CVE-2020-10534
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-…
Mediawiki
after 1.34.0
HIGH 8.1
CVE-2012-4381
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attacke…
Mediawiki
1.18.5 / 1.19.2+
MEDIUM 6.1
CVE-2013-6451
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to …
Mediawiki
1.19.10 / 1.21.4+
MEDIUM 5.3
CVE-2013-6455
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via …
Mediawiki
1.19.10 / 1.21.4+
MEDIUM 5.9
CVE-2014-9481
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted mod…
Mediawiki
1.19.23 / 1.22.15+
MEDIUM 6.1
CVE-2020-6163
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in t…
Mediawiki
Patch available
MEDIUM 6.1
CVE-2019-19910
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouse…
Mediawiki
Patch available
MEDIUM 6.1
CVE-2013-4303
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not prop…
Mediawiki
1.19.8 / 1.20.7+
MEDIUM 6.1
CVE-2019-19708
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
Visual Editor
after 1.34
MEDIUM 5.3
CVE-2019-18987
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been ma…
Abusefilter
after 1.34
MEDIUM 6.5
CVE-2019-18611
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made a…
Checkuser
after 1.34
MEDIUM 5.3
CVE-2019-18612
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or…
Abusefilter
after 1.34
HIGH 7.5
CVE-2012-0046
mediawiki allows deleted text to be exposed
Mediawiki
1.17.2 / 1.18.1+
MEDIUM 6.1
CVE-2019-14807
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.…
Mobilefrontend
after 1.33.0
HIGH 7.5
CVE-2019-12472
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blo…
Mediawiki
1.27.6 / 1.30.2+
MEDIUM 5.3
CVE-2018-13258
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
Mediawiki
after 1.31.1
MEDIUM 5.3
CVE-2014-1686
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
Mediawiki
No fix yet
MEDIUM 6.1
CVE-2012-4377
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.18.5 and 1.19.x before 1.19.2 allows remote attackers to inject arbitrary web script o…
Mediawiki
after 1.18.4
MEDIUM 6.1
CVE-2012-4378
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used…
Mediawiki
after 1.18.4
HIGH 7.5
CVE-2012-4380
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an accoun…
Mediawiki
after 1.18.4
MEDIUM 6.5
CVE-2012-4379
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct c…
Mediawiki
after 1.18.4
CRITICAL 9.8
CVE-2014-9487
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service…
Mediawiki
Mitigation only
CRITICAL 9.8
CVE-2015-8009
The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not …
Mediawiki
after 1.23.10
HIGH 7.5
CVE-2016-6331
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restri…
Mediawiki
after 1.23.14
HIGH 7.5
CVE-2016-6332
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain …
Mediawiki
after 1.23.14
HIGH 7.5
CVE-2016-6335
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows r…
Mediawiki
after 1.23.14
HIGH 7.5
CVE-2016-6337
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights …
Mediawiki
Patch available