Vulnerabilities > Mediawiki

DATE CVE VULNERABILITY TITLE RISK
2022-07-02 CVE-2022-34911 Cross-site Scripting vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1.
network
mediawiki CWE-79
4.3
2022-07-02 CVE-2022-34912 Unspecified vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1.
network
mediawiki
4.3
2022-06-28 CVE-2022-34750 Allocation of Resources Without Limits or Throttling vulnerability in Mediawiki
An issue was discovered in MediaWiki through 1.38.1.
network
low complexity
mediawiki CWE-770
5.0
2022-05-02 CVE-2022-29969 Cross-site Scripting vulnerability in Mediawiki RSS for Mediawiki
The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).
network
mediawiki CWE-79
4.3
2022-04-30 CVE-2022-28323 Unspecified vulnerability in Mediawiki
An issue was discovered in MediaWiki through 1.37.2.
network
low complexity
mediawiki
5.0
2022-04-29 CVE-2022-29903 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration.
network
mediawiki CWE-352
4.3
2022-04-29 CVE-2022-29904 SQL Injection vulnerability in Mediawiki
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
network
low complexity
mediawiki CWE-89
7.5
2022-04-29 CVE-2022-29905 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.
network
mediawiki CWE-352
4.3
2022-04-29 CVE-2022-29906 Incorrect Authorization vulnerability in Mediawiki
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
network
low complexity
mediawiki CWE-863
7.5
2022-04-29 CVE-2022-29907 Cross-site Scripting vulnerability in Mediawiki
The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise link messages.
network
mediawiki CWE-79
4.3