Vulnerabilities > Mediawiki

DATE CVE VULNERABILITY TITLE RISK
2022-02-18 CVE-2017-0371 Unspecified vulnerability in Mediawiki
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
network
low complexity
mediawiki
7.5
2022-01-24 CVE-2022-21710 Cross-site Scripting vulnerability in Mediawiki Shortdescription
ShortDescription is a MediaWiki extension that provides local short description support.
network
low complexity
mediawiki CWE-79
6.1
2022-01-10 CVE-2021-46146 Cross-site Scripting vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-79
5.4
2022-01-10 CVE-2021-46147 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-352
8.8
2022-01-10 CVE-2021-46148 Information Exposure vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-200
6.5
2022-01-10 CVE-2021-46149 Resource Exhaustion vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-400
7.5
2022-01-10 CVE-2021-46150 Cross-site Scripting vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-79
4.8
2021-12-24 CVE-2021-45471 In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
network
low complexity
mediawiki fedoraproject
5.3
2021-12-24 CVE-2021-45472 Cross-site Scripting vulnerability in multiple products
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
network
low complexity
mediawiki fedoraproject CWE-79
6.1
2021-12-24 CVE-2021-45473 Cross-site Scripting vulnerability in multiple products
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
network
low complexity
mediawiki fedoraproject CWE-79
6.1