Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 5

Found 100 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-32080 Cross-origin data leak in mobilefrontend via lazy load images The Wikimedia FoundationMediawiki - Mobile Frontend Extension--2025-04-11 16:24:00 Deep Dive
CVE-2025-32076 Evil regex used to process user-provided data in VisualData The Wikimedia FoundationMediawiki - Visual Data Extension--2025-04-11 16:23:36 Deep Dive
CVE-2025-32074 XSSes in Extension:ConfirmAccount The Wikimedia FoundationMediawiki - Confirm Account Extension--2025-04-11 16:22:23 Deep Dive
CVE-2025-32075 IP and user agent leaks in Extension:Tabs The Wikimedia FoundationMediawiki - Tabs Extension--2025-04-11 16:22:00 Deep Dive
CVE-2025-32067 i18n XSS vulnerability in message growthexperiments The Wikimedia FoundationMediawiki - Growth Experiments Extension--2025-04-11 16:21:34 Deep Dive
CVE-2025-32068 Revoking authorization of OAuth2 consumer does not invalidate refresh tokens The Wikimedia FoundationMediawiki - OAuth Extension--2025-04-11 16:21:12 Deep Dive
CVE-2025-32069 Wikitext stored XSS on filepages due to dangerous WBMI serialization The Wikimedia FoundationMediawiki - Wikibase Media Info Extension--2025-04-11 16:20:49 Deep Dive
CVE-2025-32070 XSSes in AJAXPoll The Wikimedia FoundationMediawiki - AJAX Poll Extension--2025-04-11 16:20:24 Deep Dive
CVE-2025-32071 Wikibase CommonsInlineImageFormatter: i18n XSS The Wikimedia FoundationMediawiki - Wikidata Extension--2025-04-11 16:19:46 Deep Dive
CVE-2025-23074 Special:EditProfile exposes the contents of profile fields marked "hidden"/friends or "friends of friends" when the privileged user isn't a friend of the user whose profile they edit(ed) Wikimedia FoundationMediawiki - SocialProfile Extension 低危 -2025-01-14 18:58:20 Deep Dive
CVE-2025-23073 API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter Wikimedia FoundationMediawiki - GlobalBlocking Extension 中危 -2025-01-14 18:45:32 Deep Dive
CVE-2025-23072 XSS in Special:RefreshSpecial Wikimedia FoundationMediawiki - RefreshSpecial Extension 中危 -2025-01-14 18:29:21 Deep Dive
CVE-2025-23081 Various security vulnerabilities in Extension:DataTransfer Wikimedia FoundationMediawiki - DataTransfer Extension 中危 -2025-01-14 16:56:42 Deep Dive
CVE-2025-23080 XSSes in Special:BadgeView Wikimedia FoundationMediawiki - OpenBadges Extension 中危 -2025-01-14 16:40:42 Deep Dive
CVE-2025-23079 XSSes in Extension:ArticleFeedbackv5 Wikimedia FoundationMediawiki - ArticleFeedbackv5 extension 中危 -2025-01-10 19:03:15 Deep Dive
CVE-2025-23078 XSS in BreadCrumbs2 Wikimedia FoundationMediawiki - Breadcrumbs2 extension 中危 -2025-01-10 17:57:21 Deep Dive
CVE-2024-47841 Path traversal when loading stylesheets The Wikimedia FoundationMediawiki - CSS Extension 中危 -2024-10-05 01:02:32 Deep Dive
CVE-2024-47845 CSS sanitizer used incorrectly, and is easily bypassed The Wikimedia FoundationMediawiki - CSS Extension 中危 -2024-10-05 00:09:09 Deep Dive
CVE-2017-20175 DaSchTour matomo-mediawiki-extension Username Piwik.hooks.php cross site scripting DaSchTourmatomo-mediawiki-extension Low 2.6 2023-02-05 19:57:03 Deep Dive
CVE-2017-0372 Parameters injection in SyntaxHighlight results in multiple vulnerabilities mediawikimediawiki (SyntaxHighlight extension) 超危 -2018-04-13 16:00:00 Deep Dive