Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown

CVE-2022-34911

Disclosure Date: July 02, 2022 (last updated November 08, 2023)
An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().
Attacker Value
Unknown

CVE-2020-25828

Disclosure Date: September 27, 2020 (last updated February 22, 2025)
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (which can be based on user input). (When jqueryMsg is loaded, it correctly accepts only whitelisted tags in message contents, and escapes all parameters. Situations with an unloaded jqueryMsg are rare in practice, but can for example occur for Special:SpecialPages on a wiki with no extensions installed.)
Attacker Value
Unknown

CVE-2020-6163

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).
Attacker Value
Unknown

CVE-2019-19910

Disclosure Date: December 19, 2019 (last updated November 27, 2024)
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client's IP address). This can occur within a talk page topical header that is viewed within a mobile (MobileFrontend) context.
Attacker Value
Unknown

Information disclosure in Special:Redirect/logid

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
0
Attacker Value
Unknown

$wgRateLimits entry for 'user' overrides 'newbie'

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
0
Attacker Value
Unknown

BotPasswords can bypass CentralAuth's account lock

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
0
Attacker Value
Unknown

CVE-2014-2853

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.
0
Attacker Value
Unknown

CVE-2012-2698

Disclosure Date: June 29, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.17.5, 1.18.x before 1.18.4, and 1.19.x before 1.19.1 allows remote attackers to inject arbitrary web script or HTML via the uselang parameter to index.php/Main_page.
0
Attacker Value
Unknown

CVE-2011-1766

Disclosure Date: May 23, 2011 (last updated October 04, 2023)
includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.
0