Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-3550: MediaWiki

Mediawiki v1.40.0 does not validate namespaces used in XML files.

Therefore, if the instance administrator allows XML file uploads,

a remote attacker with a low-privileged user account can use this

exploit to become an administrator by sending a malicious link to

the instance administrator.

CVE
#web

(Redirected from MediaWiki/)

MediaWiki is a collaboration and documentation platform brought to you by a vibrant community.

The MediaWiki software is used by tens of thousands of websites and thousands of companies and organisations. It powers Wikipedia and also this website. MediaWiki helps you collect and organise knowledge and make it available to people. It’s powerful, multilingual, free and open, extensible, customisable, reliable, and free of charge. Find out more and if MediaWiki is right for you.

Set up and run MediaWiki

Edit and use MediaWiki

Develop and extend code

Get help and contribute

  • Cannot find the answer to a problem with MediaWiki? Ask the support desk!
  • Get involved as a translator, designer, documentation writer, tester, tech ambassador, or developer
  • Report wrong software behaviour or a feature proposal

News

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907