Show filters
373 Total Results
Displaying 11-20 of 373
Sort by:
Attacker Value
Unknown

CVE-2024-47848

Disclosure Date: October 05, 2024 (last updated October 05, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.
0
Attacker Value
Unknown

CVE-2024-47536

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
0
Attacker Value
Unknown

CVE-2024-40605

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
Attacker Value
Unknown

CVE-2024-40604

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries.
Attacker Value
Unknown

CVE-2024-40603

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request.
Attacker Value
Unknown

CVE-2024-40602

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
Attacker Value
Unknown

CVE-2024-40601

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
Attacker Value
Unknown

CVE-2024-40600

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
Attacker Value
Unknown

CVE-2024-40599

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries.
Attacker Value
Unknown

CVE-2024-40598

Disclosure Date: July 07, 2024 (last updated July 10, 2024)
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)