Vulnerabilities > Mediawiki > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-09-29 | CVE-2021-42047 | Cross-site Scripting vulnerability in Mediawiki An issue was discovered in the Growth extension in MediaWiki through 1.36.2. | 5.4 |
2022-09-29 | CVE-2021-42048 | Cross-site Scripting vulnerability in Mediawiki An issue was discovered in the Growth extension in MediaWiki through 1.36.2. | 4.8 |
2022-09-29 | CVE-2021-42049 | Unspecified vulnerability in Mediawiki An issue was discovered in the Translate extension in MediaWiki through 1.36.2. | 6.5 |
2022-09-19 | CVE-2022-28201 | Uncontrolled Recursion vulnerability in multiple products An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. | 4.4 |
2022-09-02 | CVE-2022-39194 | Resource Exhaustion vulnerability in Mediawiki An issue was discovered in the MediaWiki through 1.38.2. | 4.9 |
2022-07-02 | CVE-2022-34911 | Cross-site Scripting vulnerability in multiple products An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. | 6.1 |
2022-07-02 | CVE-2022-34912 | An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. | 6.1 |
2022-05-02 | CVE-2022-29969 | Cross-site Scripting vulnerability in Mediawiki RSS for Mediawiki The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true). | 6.1 |
2022-04-29 | CVE-2022-29903 | Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. | 4.3 |
2022-04-29 | CVE-2022-29905 | Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF. | 4.3 |