NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27575 | CVE-2015-6731 | Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via a (1) section_*, (2) template_*, (3) label_*, or (4) new_template parameter to Special:CreateForm or (5) target or (6) alt_form parameter to Special:FormEdit. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27574 | CVE-2015-6730 | Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter, which is not properly handled in an error page, related to "ForeignAPI images." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27573 | CVE-2015-6729 | Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the rel404 parameter, which is not properly handled in an error page. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27572 | CVE-2015-6728 | The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection via a timing attack. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
| 27571 | CVE-2015-6727 | The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text. | 2 | 5 | Medium | 2017-01-19 | 2015-09-02 | View |
Page 2836 of 17672, showing 5 records out of 88360 total, starting on record 14176, ending on 14180