Vulnerabilities > Mediawiki

DATE CVE VULNERABILITY TITLE RISK
2023-10-09 CVE-2023-45367 Unspecified vulnerability in Mediawiki
An issue was discovered in the CheckUser extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
network
low complexity
mediawiki
6.5
2023-09-25 CVE-2023-3550 Cross-site Scripting vulnerability in multiple products
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
network
low complexity
mediawiki debian CWE-79
7.3
2023-08-20 CVE-2023-36674 Unspecified vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1.
network
low complexity
mediawiki
5.3
2023-06-30 CVE-2023-37300 Unspecified vulnerability in Mediawiki
An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3.
network
low complexity
mediawiki
5.3
2023-06-30 CVE-2023-37301 Unspecified vulnerability in Mediawiki
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3.
network
low complexity
mediawiki
5.3
2023-06-30 CVE-2023-37302 Cross-site Scripting vulnerability in Mediawiki
An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3.
network
low complexity
mediawiki CWE-79
6.1
2023-06-30 CVE-2023-37303 Unspecified vulnerability in Mediawiki
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.
network
low complexity
mediawiki
critical
9.8
2023-06-30 CVE-2023-37304 Cross-site Scripting vulnerability in Mediawiki
An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3.
network
low complexity
mediawiki CWE-79
5.4
2023-06-30 CVE-2023-37305 Unspecified vulnerability in Mediawiki
An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3.
network
low complexity
mediawiki
5.3
2023-06-29 CVE-2023-37251 Cross-site Scripting vulnerability in Mediawiki
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3.
network
low complexity
mediawiki CWE-79
6.1