mediawiki vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the mediawiki package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

*
  • M
CVE-2024-34502

*
  • M
Resource Exhaustion

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
CVE-2023-45362

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
CVE-2023-36674

*
  • L
Cross-site Scripting (XSS)

*
  • L
CVE-2023-29141

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • L
Information Exposure

*
  • L
Information Exposure

*
  • M
CVE-2022-41767

*
  • L
Cross-site Scripting (XSS)

*
  • L
Information Exposure

*
  • L
Information Exposure

<0:1.27.4-8.el7
  • M
CVE-2023-22909

*
  • L
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
CVE-2022-34912

*
  • M
Resource Exhaustion

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • M
Resource Exhaustion

*
  • M
Incorrect Authorization

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
Improper Resource Shutdown or Release

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Incorrect Authorization

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Privilege Management

*
  • M
Improper Privilege Management

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • H
Incorrect Default Permissions

*
  • H
Incorrect Default Permissions

*
  • M
Missing Authentication for Critical Function

*
  • M
Missing Authentication for Critical Function

*
  • M
Incorrect Authorization

*
  • M
Incorrect Authorization

*
  • M
Improper Preservation of Permissions

*
  • M
Improper Preservation of Permissions

*
  • L
Improper Authentication

*
  • L
Improper Authentication

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Incorrect Authorization

*
  • M
Incorrect Authorization

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
Information Exposure

*
  • L
Information Exposure

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • L
Open Redirect

*
  • L
Open Redirect

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
Information Exposure

*
  • L
Information Exposure

*
  • M
Open Redirect

*
  • M
Open Redirect

*
  • M
Improper Neutralization of Special Elements

*
  • M
Improper Neutralization of Special Elements

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • L
Information Exposure

*
  • L
Information Exposure

<0:1.27.7-1.el7
  • L
Information Exposure

*
  • L
Cross-site Scripting (XSS)

<0:1.27.7-1.el7
  • L
Cross-site Scripting (XSS)

*
  • L
Cross-site Scripting (XSS)

<0:1.27.7-1.el7
  • L
Improper Authorization

<0:1.27.7-1.el7
  • L
Improper Authorization

*
  • L
Improper Authorization

<0:1.27.7-1.el7