Miraheze
Miraheze Createwiki: vulnerabilities and CVEs
Miraheze Createwiki has 6 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47781 | Medium (5.3) | 0.33% | — | Oct 7, 2024 | CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displayed in the request… |
| CVE-2024-34701 | Medium (5.9) | 0.65% | — | May 14, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm… |
| CVE-2024-29898 | Medium (6.5) | 0.69% | — | Mar 28, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki requests to private wikis that added… |
| CVE-2024-29897 | Medium (4.9) | 0.71% | — | Mar 28, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm to access suppressed wiki requests by going to the… |
| CVE-2024-29883 | Medium (4.9) | 0.60% | — | Mar 26, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those with the `(createwiki)` user right… |
| CVE-2022-24813 | Medium (5.3) | 1.0% | — | Apr 4, 2022 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using Special:RequestWikiQueue when sent directly via POST. A patch for this… |