Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103047 | 1 Wikimedia | 1 Mediawiki - Centralauth Extension | 2026-09-30 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-100244 | 1 Wikimedia | 1 Mediawiki - Centralauth Extension | 2026-09-30 | 7.5 High |
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-103442 | 1 Wikimedia | 1 Mediawiki - Centralauth Extension | 2026-09-30 | N/A |
| External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-39937 | 1 Wikimedia | 1 Mediawiki - Centralauth Extension | 2026-04-09 | N/A |
| Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45. | ||||
Page 1 of 1.