MediaWiki

MediaWiki is a free software wiki package written in PHP originally for use on Wikipedia. It is now used by several other projects of the non-profit Wikimedia Foundation and by many other wikis. MediaWiki is designed to be run on a large server farm for a website that gets millions of hits per day.

Severity Summary:

Critical: 18 High: 63 Medium: 267 Low: 12
Reference
Title
Severity
MediaWiki Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
High
MediaWiki Other Vulnerability
High
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability
High
MediaWiki Improper Restriction of Excessive Authentication Attempts Vulnerability
High
MediaWiki Uncontrolled Resource Consumption Vulnerability
High
MediaWiki Improper Handling of Exceptional Conditions Vulnerability
High
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability
High
MediaWiki Other Vulnerability
High
MediaWiki Improper Authentication Vulnerability
High
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
High
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability
High
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
High
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability
High
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability
High
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability
High
MediaWiki Resource Management Errors Vulnerability
High
MediaWiki Resource Management Errors Vulnerability
High
MediaWiki Improper Input Validation Vulnerability
High
MediaWiki Improper Input Validation Vulnerability
High
MediaWiki Improper Input Validation Vulnerability
High
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability
High
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability
Medium
MediaWiki Improper Privilege Management Vulnerability
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Medium
MediaWiki Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium