Mediawiki
467 known vulnerabilities
Top Products
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka o
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing white
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules
An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related quer
An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The Special:AbuseFilter/examine form
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blo
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. Its AbuseFilterCheckMatch API reveals
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppr
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked t
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended r
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can l
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki AP
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special page
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all th
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an
An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages w
An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a ful
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it a
An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap:
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in a
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw
MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpag
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of
The PollNY extension for MediaWiki through 1.35 allows XSS via an answer option for a poll question, entered during Spec
includes/CologneBlueTemplate.php in the CologneBlue skin for MediaWiki through 1.35 allows XSS via a qbfind message supp
The RandomGameUnit extension for MediaWiki through 1.35 was not properly escaping various title-related data. When certa
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific u
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped.
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even wh
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex s
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of acto
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version o
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. F
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely usi
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creat
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messag
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching se
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and exter
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account infor
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attacker
Frequently Asked Questions
How many CVEs affect Mediawiki?
Mediawiki has 467 CVE records in our database, including 26 critical and 83 high severity vulnerabilities.
What are the most severe Mediawiki vulnerabilities?
Mediawiki has 26 critical severity (CVSS 9.0+) and 83 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mediawiki vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mediawiki products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mediawiki Vulnerabilities
CyberStrike scans your infrastructure for Mediawiki vulnerabilities and provides real-time remediation guidance.
Get Started