Total
364 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-40601 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 6.5 MEDIUM |
An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules. | |||||
CVE-2024-40600 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.8 MEDIUM |
An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |||||
CVE-2024-40599 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.8 MEDIUM |
An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |||||
CVE-2024-40598 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.3 MEDIUM |
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.) | |||||
CVE-2024-40596 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.3 MEDIUM |
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.) | |||||
CVE-2024-40604 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.8 MEDIUM |
An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries. | |||||
CVE-2024-40603 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.3 MEDIUM |
An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request. | |||||
CVE-2024-40602 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.8 MEDIUM |
An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |||||
CVE-2024-40605 | 1 Mediawiki | 1 Mediawiki | 2024-07-09 | N/A | 4.8 MEDIUM |
An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |||||
CVE-2023-45360 | 1 Mediawiki | 1 Mediawiki | 2024-07-03 | N/A | 5.4 MEDIUM |
An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers. | |||||
CVE-2023-51704 | 1 Mediawiki | 1 Mediawiki | 2024-06-10 | N/A | 6.1 MEDIUM |
An issue was discovered in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. In includes/logging/RightsLogFormatter.php, group-*-member messages can result in XSS on Special:log/rights. | |||||
CVE-2023-45362 | 1 Mediawiki | 1 Mediawiki | 2024-06-10 | N/A | 4.3 MEDIUM |
An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak. | |||||
CVE-2023-3550 | 2 Debian, Mediawiki | 2 Debian Linux, Mediawiki | 2024-06-10 | N/A | 7.3 HIGH |
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator. | |||||
CVE-2024-23171 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 5.4 MEDIUM |
An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows XSS via the x-xss language setting for internationalization (i18n). | |||||
CVE-2024-23172 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 5.4 MEDIUM |
An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via message definitions. e.g., in SpecialCheckUserLog. | |||||
CVE-2024-23173 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 6.1 MEDIUM |
An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows XSS via artist, album, and position parameters because of applied filter values in drilldown/CargoAppliedFilter.php. | |||||
CVE-2024-23174 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 5.4 MEDIUM |
An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter-date-range-format-placeholder, pagetriage-filter-date-range-to, pagetriage-filter-date-range-from, pagetriage-filter-date-range-heading, pagetriage-filter-set-button, or pagetriage-filter-reset-button message. | |||||
CVE-2024-23177 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 6.1 MEDIUM |
An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter. | |||||
CVE-2024-23178 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 5.4 MEDIUM |
An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message. | |||||
CVE-2024-23179 | 1 Mediawiki | 1 Mediawiki | 2024-01-18 | N/A | 6.1 MEDIUM |
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks. |