Vulnerabilities
Vulnerable Software
Mediawiki:  >> Mediawiki  >> 1.39.6  Security Vulnerabilities
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
CVSS Score
7.4
EPSS Score
0.007
Published
2024-05-05
An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.
CVSS Score
6.1
EPSS Score
0.004
Published
2024-01-12
An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.
CVSS Score
5.4
EPSS Score
0.004
Published
2024-01-12
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.
CVSS Score
6.1
EPSS Score
0.004
Published
2024-01-12


Contact Us

Shodan ® - All rights reserved