Filter
AND

Wikimedia MediaWikiCSRF

8.8
First published (updated )

Wikimedia MediaWikiAn issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. …

7.5
First published (updated )

Wikimedia MediaWikiAn issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. …

7.5
First published (updated )

Wikimedia MediaWikiAn issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allow…

7.5
First published (updated )

Wikimedia MediaWikiThe ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is bl…

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Fedoraproject FedoraMediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query pr…

7.5
First published (updated )

composer/mediawiki/coreAn issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before …

7.5
First published (updated )

Wikimedia MediaWikiAn issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.…

7.5
First published (updated )

Wikimedia MediaWikiSQL Injection

7.5
First published (updated )

Wikimedia MediaWikiHaving LocalisationCache directory default to system tmp directory is insecure

8.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Wikimedia MediaWiki"Mark all pages visited" on the watchlist does not require a CSRF token

8.8
First published (updated )

Wikimedia MediaWikiMediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two…

7.5
First published (updated )

Wikimedia MediaWikiEval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbi…

7.5
First published (updated )

Wikimedia MediaWikiCSRF

7.5
First published (updated )

Wikimedia MediaWikiPath Traversal

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Wikimedia MediaWikiInput Validation

7.5
First published (updated )

Wikimedia MediaWikiThe CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.2…

7.5
First published (updated )

Wikimedia MediaWikiBuffer Overflow

7.5
First published (updated )

Wikimedia MediaWikiThe CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x befor…

7.5
First published (updated )

Wikimedia MediaWikiInput Validation

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Wikimedia MediaWikiInfoleak

7.5
First published (updated )

Wikimedia MediaWikiCommand Injection

7.5
First published (updated )

Wikimedia MediaWikiCSRF

8.8
First published (updated )

Wikimedia MediaWikiCSRF

8.8
First published (updated )

Wikimedia MediaWikiInfoleak

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Fedoraproject FedoraThe OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/i…

7.5
First published (updated )

Wikimedia MediaWikiCSRF

7.5
First published (updated )

Wikimedia MediaWikiMediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remo…

7.1
First published (updated )

Wikimedia MediaWikiMediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP,…

7.1
First published (updated )

Wikimedia MediaWikiMediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to c…

7.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203