Total vulnerabilities in the database
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file.
Software | From | Fixed in |
---|---|---|
mediawiki / mediawiki | 1.37.0 | 1.37.1 |
mediawiki / mediawiki | - | 1.35.5 |
mediawiki / mediawiki | 1.36.0 | 1.36.3 |