Show filters
381 Total Results
Displaying 61-70 of 381
Sort by:
Attacker Value
Unknown

CVE-2023-22911

Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Attacker Value
Unknown

CVE-2023-22909

Disclosure Date: January 10, 2023 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
Attacker Value
Unknown

CVE-2022-41767

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
Attacker Value
Unknown

CVE-2022-41765

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
Attacker Value
Unknown

CVE-2021-44856

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of the EditFilterMergedContent hook return value.
Attacker Value
Unknown

CVE-2021-44855

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
Attacker Value
Unknown

CVE-2021-44854

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.
Attacker Value
Unknown

CVE-2022-4561

Disclosure Date: December 16, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SemanticDrilldown Extension. Affected is the function printFilterLine of the file includes/specials/SDBrowseDataPage.php of the component GET Parameter Handler. The manipulation of the argument value leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 6e18cf740a4548166c1d95f6d3a28541d298a3aa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215964.
Attacker Value
Unknown

CVE-2021-42049

Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in the Translate extension in MediaWiki through 1.36.2. Oversighters cannot undo revisions or oversight on pages where they suppressed information (such as PII). This allows oversighters to whitewash revisions.
Attacker Value
Unknown

CVE-2021-42048

Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.