Filter
AND
-Infinity
0

MediaWikiPath traversal when loading stylesheets

7.5
First published (updated )

MediaWikiCSS sanitizer used incorrectly, and is easily bypassed

8.2
First published (updated )

MediaWikiXSS

7.4
EPSS
0.04%
First published (updated )

MediaWikiAn issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x …

7.5
EPSS
0.04%
First published (updated )

composer/mediawiki/coreAn issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before …

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MediaWikiAn issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.…

7.5
First published (updated )

MediaWikiA denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php…

7.5
First published (updated )

MediaWikiA denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.…

7.5
First published (updated )

MediaWikiAn issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is curren…

7.5
First published (updated )

MediaWikiAn issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because …

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MediaWikiMediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remot…

7.5
First published (updated )

MediaWikiCSRF

8.8
First published (updated )

MediaWikiAn issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. …

7.5
First published (updated )

MediaWikiAn issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. …

7.5
First published (updated )

MediaWikiThe ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is bl…

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Red Hat FedoraMediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query pr…

7.5
First published (updated )

MediaWikiAn issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allow…

7.5
First published (updated )

MediaWikiAn issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRe…

7.5
First published (updated )

MediaWikiAn issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed…

8.8
First published (updated )

MediaWikiIn MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots hav…

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MediaWikiInput Validation

7.5
First published (updated )

MediaWikiCSRF

8.8
First published (updated )

MediaWikiThe API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, all…

7.5
First published (updated )

MediaWikiInput Validation

7.5
First published (updated )

MediaWikiAn issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the abi…

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MediaWikiCSRF

8.8
First published (updated )

debian/mediawikiXSS

7.5
First published (updated )

composer/mediawiki/coreTOTP throttle not enforced cross-wiki

7.5
First published (updated )

MediaWikiAn information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34…

7.5
First published (updated )

MediaWikiAn issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can i…

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203