Skip to main content

Vendor archive

mediawiki CVEs

Beta · best-effort

463 CVEs tagged to vendor mediawiki19 Critical, 73 High, 314 Medium, 27 Low, 30 Unrated.

CVE-2019-12473

Published Jul 10, 2019

Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.3…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12472

Published Jul 10, 2019

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by usi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12471

Published Jul 10, 2019

Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that s…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12468

Published Jul 10, 2019

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authenticati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12467

Published Jul 10, 2019

MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13258

Published Oct 4, 2018

Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1686

Published Apr 16, 2018

MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8008

Published Dec 29, 2017

The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8814

Published Nov 15, 2017

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 463 CVEsPage 12 of 19