Show filters
373 Total Results
Displaying 91-100 of 373
Sort by:
Attacker Value
Unknown
CVE-2022-29905
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.
0
Attacker Value
Unknown
CVE-2022-29904
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
0
Attacker Value
Unknown
CVE-2022-29903
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. The attacker must trigger a POST request to Special:PrivateDomains.
0
Attacker Value
Unknown
CVE-2022-28209
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.
0
Attacker Value
Unknown
CVE-2022-28206
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights.
0
Attacker Value
Unknown
CVE-2022-28205
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.
0
Attacker Value
Unknown
CVE-2022-28202
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
0
Attacker Value
Unknown
CVE-2017-0371
Disclosure Date: February 18, 2022 (last updated October 07, 2023)
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
0
Attacker Value
Unknown
CVE-2021-45474
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
0
Attacker Value
Unknown
CVE-2021-45473
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
0