Total vulnerabilities in the database
An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via the rev-deleted-user, pagetriage-tags-quickfilter-label, pagetriage-triage, pagetriage-filter-date-range-format-placeholder, pagetriage-filter-date-range-to, pagetriage-filter-date-range-from, pagetriage-filter-date-range-heading, pagetriage-filter-set-button, or pagetriage-filter-reset-button message.
Software | From | Fixed in |
---|---|---|
mediawiki / mediawiki | - | 1.35.14 |
mediawiki / mediawiki | 1.36.0 | 1.39.6 |
mediawiki / mediawiki | 1.40.0 | 1.40.2 |