Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
596 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.41% | — | Mediawiki Cargo | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1. | |
| Analizada | Media (6.9) | 0.29% | — | Mediawiki Cargo | 5/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1. | |
| Aplazada | Media (6.9) | 0.52% | — | Wikimedia Mediawiki - PagetriageAI | 5/10/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2. | |
| Analizada | Media (5.3) | 0.45% | — | Mediawiki | 4/10/2024 | 17/6/2026 | An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter. | |
| Aplazada | Baja (3.5) | 0.34% | — | Mediawiki DatadumpAI | 2/10/2024 | 17/6/2026 | DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are edited (which requires the… | |
| Modificada | Media (4.8) | 0.32% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |
| Modificada | Media (4.8) | 0.32% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries. | |
| Modificada | Media (4.3) | 0.20% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF to alter data via a GET request. | |
| Modificada | Media (4.8) | 0.28% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |
| Modificada | Media (6.5) | 0.16% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules. | |
| Modificada | Media (4.8) | 0.30% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |
| Modificada | Media (4.8) | 0.30% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-level menu entries. | |
| Modificada | Media (4.3) | 0.33% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.) | |
| Analizada | Alta (7.5) | 0.40% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.) | |
| Modificada | Media (4.3) | 0.33% | — | Mediawiki | 7/7/2024 | 17/6/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.) | |
| Aplazada | Media (5.9) | 0.65% | — | Miraheze CreatewikiAIMediawikiAI | 14/5/2024 | 17/6/2026 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requester at the wiki where the wiki request was made. This allows them to go… | |
| Modificada | Alta (7.4) | 0.67% | — | MediawikiFedoraproject Fedora | 5/5/2024 | 17/6/2026 | An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000. | |
| Modificada | Alta (7.5) | 0.90% | — | MediawikiFedoraproject Fedora | 5/5/2024 | 17/6/2026 | An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time,… | |
| Modificada | Crítica (9.8) | 0.41% | — | MediawikiFedoraproject Fedora | 5/5/2024 | 17/6/2026 | An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token. | |
| Modificada | Media (6.1) | 0.47% | — | MediawikiFedoraproject Fedora | 5/5/2024 | 17/6/2026 | An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class. | |
| Aplazada | Alta (8.6) | 0.59% | — | Mediawiki CargoAI | 27/3/2024 | 17/6/2026 | An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit. | |
| Modificada | Media (6.1) | 0.43% | — | Mediawiki | 12/1/2024 | 17/6/2026 | An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks. | |
| Modificada | Media (5.4) | 0.41% | — | Mediawiki | 12/1/2024 | 17/6/2026 | An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message. | |
| Modificada | Media (6.1) | 0.42% | — | Mediawiki | 12/1/2024 | 17/6/2026 | An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter. | |
| Modificada | Media (5.4) | 0.41% | — | Mediawiki | 12/1/2024 | 17/6/2026 | An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter-date-range-format-placeholder, pagetriage-filter-date-range-to,… |