Vulnerabilities > Mediawiki > Mediawiki > 1.33.3

DATE CVE VULNERABILITY TITLE RISK
2020-09-27 CVE-2020-25813 In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
network
low complexity
mediawiki fedoraproject
5.3
2020-06-24 CVE-2020-15005 In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them.
network
high complexity
mediawiki fedoraproject debian
3.1
2020-06-02 CVE-2020-10959 Open Redirect vulnerability in Mediawiki
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
network
mediawiki CWE-601
5.8
2020-04-03 CVE-2020-10960 Improper Encoding or Escaping of Output vulnerability in Mediawiki
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page.
network
low complexity
mediawiki CWE-116
5.0
2020-03-12 CVE-2020-10534 Improper Privilege Management vulnerability in Mediawiki
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges.
network
low complexity
mediawiki CWE-269
7.5