Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Scribunto HIGH 7.5
CVE-2026-34089

Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.

Fix: 1.45.2+
Fix from $1,950 2026-05-11
Campaignevents MEDIUM 5.3
CVE-2026-0817

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki …

Patch available
Fix from $1,600 2026-01-09
Wikibase MEDIUM 5.4
CVE-2026-22710

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wik…

Patch available
Fix from $1,600 2026-01-09
Mediawiki Extensions Uploadwizard MEDIUM 6.1
CVE-2026-0671

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadW…

Patch available
Fix from $1,600 2026-01-08
Wikimedia Extensions Css HIGH 7.5
CVE-2024-47841EPSS 35%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension al…

Fix: 1.39.9 / 1.41.3+
Fix from $1,950 2024-10-05
Wikimedia Extensions Css HIGH 8.2
CVE-2024-47845

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects …

Fix: 1.39.9 / 1.41.3+
Fix from $1,950 2024-10-05
Mediawiki Extensions I18ntags MEDIUM 6.1
CVE-2018-25065

A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects some unknown processing of the…

Fix: 2018-08-06+
Fix from $1,600 2023-01-05
Analytics Quarry Web MEDIUM 6.1
CVE-2020-36324

Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.

Fix: 2020-12-15+
Fix from $1,600 2021-04-21
Parsoid MEDIUM 6.1
CVE-2021-30458

An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php wil…

Fix: 0.11.1 / 0.12.2+
Fix from $1,600 2021-04-09
Wikidata Query Gui MEDIUM 6.1
CVE-2019-19327

ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results a…

Fix: after 0.3.5
Fix from $1,600 2019-11-27
Wikidata Query Gui MEDIUM 6.1
CVE-2019-19328

ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE…

Fix: after 0.3.5
Fix from $1,600 2019-11-27
Wikidata Query Gui MEDIUM 6.1
CVE-2019-19329

In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary J…

Fix: after 0.3.5
Fix from $1,600 2019-11-27