Vulnerabilities > Mediawiki
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-29 | CVE-2022-29904 | SQL Injection vulnerability in Mediawiki The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. | 9.8 |
2022-04-29 | CVE-2022-29905 | Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF. | 4.3 |
2022-04-29 | CVE-2022-29906 | Missing Authorization vulnerability in Mediawiki The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user. | 9.8 |
2022-04-29 | CVE-2022-29907 | Cross-site Scripting vulnerability in Mediawiki The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise link messages. | 6.1 |
2022-04-21 | CVE-2022-29547 | Incorrect Default Permissions vulnerability in Mediawiki Createredirect The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. | 7.5 |
2022-03-30 | CVE-2022-28205 | Unspecified vulnerability in Mediawiki An issue was discovered in MediaWiki through 1.37.1. | 9.8 |
2022-03-30 | CVE-2022-28206 | Unspecified vulnerability in Mediawiki An issue was discovered in MediaWiki through 1.37.1. | 9.8 |
2022-03-30 | CVE-2022-28209 | Unspecified vulnerability in Mediawiki An issue was discovered in Mediawiki through 1.37.1. | 9.8 |
2022-03-30 | CVE-2022-28202 | Cross-site Scripting vulnerability in multiple products An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. | 6.1 |
2022-02-18 | CVE-2017-0371 | Unspecified vulnerability in Mediawiki MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute. | 7.5 |