📦 Mediawiki

by Mediawiki

🔍 What is Mediawiki?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-34502

CRITICAL CVSS 9.8 May 5, 2024

This vulnerability allows unauthenticated attackers to merge lexemes in WikibaseLexeme without proper authorization. It affects MediaWiki installations with the WikibaseLexeme extension enabled. The i...

CVE-2023-37303

CRITICAL CVSS 9.8 Jun 30, 2023

This vulnerability in the CheckUser extension for MediaWiki allows denial-of-service attacks when attempting to block users, causing temporary browser hangs and database disconnection errors. It affec...

CVE-2023-29141

CRITICAL CVSS 9.8 Mar 31, 2023

This vulnerability in MediaWiki allows attackers to trigger automatic IP blocking by manipulating the X-Forwarded-For HTTP header. It affects MediaWiki instances that process untrusted headers, potent...

CVE-2022-29904

CRITICAL CVSS 9.8 Apr 29, 2022

This CVE describes an SQL injection vulnerability in the SemanticDrilldown extension for MediaWiki. Attackers can exploit certain '-' and '_' constraints to execute arbitrary SQL commands. All MediaWi...

CVE-2022-29906

CRITICAL CVSS 9.8 Apr 29, 2022

This vulnerability allows attackers to bypass authorization checks in the QuizGame extension for MediaWiki, granting unauthorized access to admin API functions. Any MediaWiki installation with the Qui...

CVE-2022-28205

CRITICAL CVSS 9.8 Mar 30, 2022

A critical vulnerability in MediaWiki's CentralAuth extension allows improper handling of group expiration timestamps (TTL), potentially enabling privilege escalation. This affects MediaWiki installat...

CVE-2022-28209

CRITICAL CVSS 9.8 Mar 30, 2022

This vulnerability in MediaWiki's AntiSpoof extension allows users with the 'override-antispoof' permission to bypass username spoofing checks. It affects MediaWiki installations with the AntiSpoof ex...

CVE-2021-31556

CRITICAL CVSS 9.8 Aug 12, 2021

This vulnerability in MediaWiki's OAuth extension allows attackers to cause denial of service or potentially execute arbitrary code by submitting RSA keys that exceed MySQL blob storage limits. It aff...

CVE-2021-36126

CRITICAL CVSS 9.8 Jul 2, 2021

This vulnerability in MediaWiki's AbuseFilter extension causes a fatal error when both the content language and English versions of the MediaWiki:Abusefilter-blocker message are invalid. This prevents...

CVE-2021-36128

CRITICAL CVSS 9.8 Jul 2, 2021

This vulnerability in MediaWiki's CentralAuth extension allows improper implementation of autoblocks for suppression blocks. Attackers could bypass account blocks or suppression mechanisms, affecting ...

CVE-2024-40597

HIGH CVSS 7.5 Jul 7, 2024

The CheckUser extension for MediaWiki fails to respect the log_deleted attribute, allowing unauthorized users to view suppressed log information. This affects MediaWiki installations with the CheckUse...

CVE-2024-34507

HIGH CVSS 7.4 May 5, 2024

This vulnerability allows cross-site scripting (XSS) attacks in MediaWiki due to improper handling of the escape character (0x1b) in comment parsing. Attackers can inject malicious scripts that execut...

CVE-2023-45371

HIGH CVSS 7.5 Oct 9, 2023

This vulnerability allows attackers to perform unlimited item merging operations in Wikibase, potentially disrupting data integrity and availability. It affects MediaWiki installations with the Wikiba...

CVE-2023-45363

HIGH CVSS 7.5 Oct 9, 2023

This vulnerability in MediaWiki's ApiPageSet.php allows attackers to trigger an infinite loop when querying pages with specific redirect and title conversion parameters, causing denial of service thro...

CVE-2022-28323

HIGH CVSS 7.5 Apr 30, 2022

The SecurePoll extension in MediaWiki through version 1.37.2 contains an information disclosure vulnerability where sorting by timestamp can leak sensitive data. This affects MediaWiki installations w...

CVE-2017-0371

HIGH CVSS 7.5 Feb 18, 2022

This vulnerability allows remote attackers to discover the IP addresses of Wiki visitors through a CSS injection attack. Attackers can embed malicious CSS in wiki pages that forces visitors' browsers ...

CVE-2021-46149

HIGH CVSS 7.5 Jan 10, 2022

This vulnerability allows attackers to cause denial of service by searching for extremely long language names in MediaWiki's Language Name Search feature. It affects MediaWiki installations running vu...

CVE-2021-46147

HIGH CVSS 8.8 Jan 10, 2022

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in MediaWiki's MassEditRegex extension. It allows attackers to trick authenticated administrators into performing unauthorized mass...

CVE-2021-44858

HIGH CVSS 7.5 Dec 20, 2021

This vulnerability allows unauthorized users to view private pages on MediaWiki installations configured as private wikis with whitelist read restrictions. Attackers can exploit a flaw in the undo/res...

CVE-2021-41799

HIGH CVSS 7.5 Oct 11, 2021

CVE-2021-41799 is a denial-of-service vulnerability in MediaWiki's ApiQueryBacklinks feature that allows attackers to trigger full table scans, consuming excessive database resources and causing servi...

CVE-2021-41801

HIGH CVSS 8.8 Oct 11, 2021

This vulnerability in MediaWiki's ReplaceText extension allows blocked users to still execute previously submitted text replacement jobs through the job queue. It affects MediaWiki installations using...

CVE-2021-42040

HIGH CVSS 7.5 Oct 6, 2021

This vulnerability in MediaWiki's Loops extension allows attackers to trigger infinite loops through parser functions, causing memory exhaustion and php-fpm hangs. It affects MediaWiki installations w...

CVE-2021-36125

HIGH CVSS 7.5 Jul 2, 2021

This vulnerability in MediaWiki's CentralAuth extension allows attackers to cause denial of service through infinite loops when processing username rename requests with overly long names. It affects M...

CVE-2021-36132

HIGH CVSS 8.8 Jul 2, 2021

This vulnerability in MediaWiki's FileImporter extension allows users with insufficient permissions to upload files when certain relaxed configurations of $wgFileImporterRequiredRight are used. It aff...

CVE-2021-31555

HIGH CVSS 7.5 Apr 22, 2021

This vulnerability in MediaWiki's OAuth extension allows attackers to submit overly long oarc_version parameters, potentially causing buffer overflows or denial of service. It affects MediaWiki instal...

CVE-2025-61645

MEDIUM CVSS 6.1 Feb 3, 2026

This is a cross-site scripting (XSS) vulnerability in MediaWiki's CodexTablePager component that allows attackers to inject malicious scripts into web pages. It affects all MediaWiki installations run...

CVE-2024-40596

MEDIUM CVSS 4.3 Jul 7, 2024

The CheckUser extension for MediaWiki has a vulnerability where the Special:Investigate feature can expose suppressed log event information that should remain hidden. This affects MediaWiki administra...

CVE-2024-40599

MEDIUM CVSS 4.8 Jul 7, 2024

This stored cross-site scripting (XSS) vulnerability in the GuMaxDD skin for MediaWiki allows attackers to inject malicious scripts into top-level menu entries. When users view the affected sidebar me...

CVE-2024-40601

MEDIUM CVSS 6.5 Jul 7, 2024

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the MediaWikiChat extension for MediaWiki. Attackers can trick authenticated users into performing unauthorized actions via the ...

CVE-2024-40603

MEDIUM CVSS 4.3 Jul 7, 2024

This CSRF vulnerability in the ArticleRatings MediaWiki extension allows attackers to manipulate article rating data without user consent. Attackers can craft malicious links or web pages that, when v...

CVE-2024-40605

MEDIUM CVSS 4.8 Jul 7, 2024

This stored cross-site scripting (XSS) vulnerability in MediaWiki's Foreground skin allows attackers to inject malicious scripts into top-level menu entries. When users view the sidebar, these scripts...