Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
596 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | MediawikiFedoraproject FedoraDebian Linux | 30/3/2022 | 17/6/2026 | An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete. | |
| Modificada | Alta (7.5) | 1.6% | — | Mediawiki | 18/2/2022 | 17/6/2026 | MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute. | |
| Modificada | Media (6.1) | 1.0% | — | Mediawiki Shortdescription | 24/1/2022 | 17/6/2026 | ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the action=info parameter, which displays the… | |
| Modificada | Media (4.8) | 0.65% | — | Mediawiki | 10/1/2022 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:October. | |
| Modificada | Alta (7.5) | 1.2% | — | Mediawiki | 10/1/2022 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search. | |
| Modificada | Media (6.5) | 1.2% | — | Mediawiki | 10/1/2022 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll instance. | |
| Modificada | Alta (8.8) | 0.53% | — | Mediawiki | 10/1/2022 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF. | |
| Modificada | Media (5.4) | 0.57% | — | Mediawiki | 10/1/2022 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file. | |
| Modificada | Media (6.1) | 0.97% | — | MediawikiFedoraproject Fedora | 24/12/2021 | 17/6/2026 | In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter. | |
| Modificada | Media (6.1) | 1.2% | — | MediawikiFedoraproject Fedora | 24/12/2021 | 17/6/2026 | In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar). | |
| Modificada | Media (6.1) | 0.97% | — | MediawikiFedoraproject Fedora | 24/12/2021 | 17/6/2026 | In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used. | |
| Modificada | Media (5.3) | 1.2% | — | MediawikiFedoraproject Fedora | 24/12/2021 | 17/6/2026 | In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. | |
| Modificada | Alta (7.5) | 1.3% | — | Mediawiki | 20/12/2021 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead. | |
| Modificada | Media (5.3) | 1.4% | — | Mediawiki | 17/12/2021 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents. | |
| Modificada | Media (6.5) | 0.87% | — | Mediawiki | 17/12/2021 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=mcrundo followed by action=mcrrestore to replace the content of any arbitrary page (that the user doesn't have edit rights for). This applies to any public wiki, or a private wiki that has… | |
| Modificada | Alta (8.8) | 1.2% | — | Mediawiki | 11/10/2021 | 17/6/2026 | The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog) | |
| Modificada | Media (5.3) | 1.8% | — | MediawikiFedoraproject Fedora | 11/10/2021 | 17/6/2026 | MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled. | |
| Modificada | Alta (7.5) | 1.7% | — | MediawikiFedoraproject Fedora | 11/10/2021 | 17/6/2026 | MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan. | |
| Modificada | Media (6.1) | 1.4% | — | MediawikiFedoraproject Fedora | 11/10/2021 | 17/6/2026 | MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page. | |
| Modificada | Media (4.8) | 0.64% | — | Mediawiki | 6/10/2021 | 17/6/2026 | An issue was discovered in the Mentor dashboard in the GrowthExperiments extension in MediaWiki through 1.36.2. The Growthexperiments-mentor-dashboard-mentee-overview-add-filter-total-edits-headline, growthexperiments-mentor-dashboard-mentee-overview-add-filter-starred-headline,… | |
| Modificada | Media (6.1) | 0.75% | — | Mediawiki | 6/10/2021 | 17/6/2026 | An issue was discovered in Special:MediaSearch in the MediaSearch extension in MediaWiki through 1.36.2. The suggestion text (a parameter to mediasearch-did-you-mean) was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the intitle: search operator within the query. | |
| Modificada | Media (4.8) | 0.55% | — | Mediawiki | 6/10/2021 | 17/6/2026 | An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript. | |
| Modificada | Media (6.1) | 0.98% | — | Mediawiki | 6/10/2021 | 17/6/2026 | An issue was discovered in CentralAuth in MediaWiki through 1.36.2. The rightsnone MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript via the setchange log. | |
| Modificada | Alta (7.5) | 1.2% | — | Mediawiki | 6/10/2021 | 17/6/2026 | An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion. | |
| Modificada | Crítica (9.8) | 1.6% | — | MediawikiFedoraproject Fedora | 12/8/2021 | 17/6/2026 | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob. |