Show filters
90 Total Results
Displaying 41-50 of 90
Sort by:
Attacker Value
Unknown

CVE-2020-35480

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.
Attacker Value
Unknown

CVE-2020-35477

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysubmit (instead of the desired behavior in which a revision-deletion form appears).
Attacker Value
Unknown

CVE-2020-35479

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.
Attacker Value
Unknown

CVE-2020-15005

Disclosure Date: June 24, 2020 (last updated November 08, 2023)
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.
Attacker Value
Unknown

CVE-2013-1817

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Attacker Value
Unknown

CVE-2013-1816

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Attacker Value
Unknown

CVE-2013-1951

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Attacker Value
Unknown

CVE-2019-16738

Disclosure Date: September 26, 2019 (last updated November 08, 2023)
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
Attacker Value
Unknown

CVE-2019-19709

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
Attacker Value
Unknown

CVE-2019-12469

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
0