Search CVE reports


Toggle filters

71 – 80 of 310 results


CVE-2023-37303

Medium priority
Needs evaluation

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message.

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-37302

Medium priority
Needs evaluation

An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js)...

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-37301

Medium priority
Needs evaluation

An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn’t use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-37300

Medium priority
Needs evaluation

An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-36675

Medium priority
Needs evaluation

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-41766

Medium priority
Needs evaluation

An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision...

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-30153

Medium priority
Ignored

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden,...

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Not affected Not affected Not affected
Show less packages

CVE-2023-29141

Medium priority
Needs evaluation

An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-47927

Medium priority
Needs evaluation

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with...

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-36649

Negligible priority
Needs evaluation

A vulnerability was found in mholt PapaParse up to 5.1.x. It has been classified as problematic. Affected is an unknown function of the file papaparse.js. The manipulation leads to inefficient regular expression complexity....

1 affected package

mediawiki

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages