Show filters
381 Total Results
Displaying 61-70 of 381
Sort by:
Attacker Value
Unknown
CVE-2023-22911
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
0
Attacker Value
Unknown
CVE-2023-22909
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
0
Attacker Value
Unknown
CVE-2022-41767
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
0
Attacker Value
Unknown
CVE-2022-41765
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
0
Attacker Value
Unknown
CVE-2021-44856
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of the EditFilterMergedContent hook return value.
0
Attacker Value
Unknown
CVE-2021-44855
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
0
Attacker Value
Unknown
CVE-2021-44854
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.
0
Attacker Value
Unknown
CVE-2022-4561
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SemanticDrilldown Extension. Affected is the function printFilterLine of the file includes/specials/SDBrowseDataPage.php of the component GET Parameter Handler. The manipulation of the argument value leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 6e18cf740a4548166c1d95f6d3a28541d298a3aa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215964.
0
Attacker Value
Unknown
CVE-2021-42049
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in the Translate extension in MediaWiki through 1.36.2. Oversighters cannot undo revisions or oversight on pages where they suppressed information (such as PII). This allows oversighters to whitewash revisions.
0
Attacker Value
Unknown
CVE-2021-42048
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
0