Show filters
373 Total Results
Displaying 91-100 of 373
Sort by:
Attacker Value
Unknown

CVE-2022-29905

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.
Attacker Value
Unknown

CVE-2022-29904

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
Attacker Value
Unknown

CVE-2022-29903

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. The attacker must trigger a POST request to Special:PrivateDomains.
Attacker Value
Unknown

CVE-2022-28209

Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.
Attacker Value
Unknown

CVE-2022-28206

Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights.
Attacker Value
Unknown

CVE-2022-28205

Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.
Attacker Value
Unknown

CVE-2022-28202

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
Attacker Value
Unknown

CVE-2017-0371

Disclosure Date: February 18, 2022 (last updated October 07, 2023)
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
Attacker Value
Unknown

CVE-2021-45474

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Attacker Value
Unknown

CVE-2021-45473

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).