Show filters
381 Total Results
Displaying 91-100 of 381
Sort by:
Attacker Value
Unknown

CVE-2022-28205

Disclosure Date: March 30, 2022 (last updated October 07, 2023)
An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.
Attacker Value
Unknown

CVE-2022-28202

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
Attacker Value
Unknown

CVE-2017-0371

Disclosure Date: February 18, 2022 (last updated October 07, 2023)
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.
Attacker Value
Unknown

CVE-2022-21710

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the action=info parameter, which displays the shortdesc property. This is achieved using the wikitext `{{SHORTDESC:<img src=x onerror=alert()>}}`. This issue has a patch in version 2.3.4.
Attacker Value
Unknown

CVE-2021-45474

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Attacker Value
Unknown

CVE-2021-45473

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).
Attacker Value
Unknown

CVE-2021-45472

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
Attacker Value
Unknown

CVE-2021-45471

Disclosure Date: December 24, 2021 (last updated October 07, 2023)
In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
Attacker Value
Unknown

CVE-2021-44858

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
Attacker Value
Unknown

CVE-2021-45038

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.