Skip to content
Noroxi

Wikimedia records

15 published records for vendor wikimedia.

All records

15 records
  • Path traversal when loading stylesheets

    MediumCVSS 6.9No exploitEPSS 35%

    wikimedia · wikimedia-extensions-cssOct 4, 2024

  • User can review/unreview articles while blocked

    MediumCVSS 6.9No exploitEPSS 1%

    the wikimedia foundation · mediawiki - pagetriageOct 4, 2024

  • CSS sanitizer used incorrectly, and is easily bypassed

    MediumCVSS 6.9No exploitEPSS 0%

    wikimedia · wikimedia-extensions-cssOct 4, 2024

  • Stored XSS through sidebar in Apex skin

    MediumCVSS 6.9No exploitEPSS 0%

    wikimedia · apexOct 4, 2024

  • In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, ar

    MediumCVSS 6.1No exploitEPSS 1%

    wikimedia · wikidata query guiNov 27, 2019

  • An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2.

    MediumCVSS 6.1No exploitEPSS 1%

    wikimedia · parsoidApr 9, 2021

  • ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entit

    MediumCVSS 6.1No exploitEPSS 1%

    wikimedia · wikidata query guiNov 27, 2019

  • ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of

    MediumCVSS 6.1No exploitEPSS 1%

    wikimedia · wikidata query guiNov 27, 2019

  • Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json con

    MediumCVSS 6.1No exploitEPSS 1%

    wikimedia · analytics-quarry-webApr 21, 2021

  • Wikimedia mediawiki-extensions-I18nTags Unlike Parser I18nTags_body.php cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    wikimedia · mediawiki-extensions-i18ntagsJan 5, 2023

  • CVE-2026-0671
    24Monitor

    Multiple stored i18n/message-key XSSes in UploadWizard

    MediumCVSS 6.1No exploitEPSS 0%

    wikimedia · mediawiki-extensions-uploadwizardJan 8, 2026

  • CVE-2026-0817
    21Monitor

    CampaignEvents API missing authorization exposes meeting and chat URLs

    MediumCVSS 5.3No exploitEPSS 0%

    wikimedia · campaigneventsJan 9, 2026

  • Memory leak in Scribunto causes runJobs.php to run out of memory

    LowCVSS 2.3No exploitEPSS 0%

    wikimedia · scribuntoMay 11, 2026

  • Stored XSS through autocomment system messages in Wikibase

    LowCVSS 2.3No exploitEPSS 0%

    wikimedia · wikibaseJan 8, 2026

  • Sanitizer::validateAttributes data-XSS

    CVSS 0.0Proof of conceptEPSS 0%

    mediawiki · mediawikiFeb 2, 2026