Show filters
373 Total Results
Displaying 181-190 of 373
Sort by:
Attacker Value
Unknown

CVE-2013-1817

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Attacker Value
Unknown

CVE-2013-1816

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Attacker Value
Unknown

CVE-2013-1951

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Attacker Value
Unknown

CVE-2012-0046

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
mediawiki allows deleted text to be exposed
Attacker Value
Unknown

CVE-2019-16738

Disclosure Date: September 26, 2019 (last updated November 08, 2023)
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
Attacker Value
Unknown

CVE-2019-19709

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Attacker Value
Unknown

CVE-2019-12469

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12470

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12471

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0
Attacker Value
Unknown

CVE-2019-12474

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0