
CVE-2014-9478 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9478
16 Jan 2015 — Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary web script or HTML via the wpInput parameter to the Special:ExpandTemplates page. Vulnerabilidad de XSS en la previsualización en la extensión ExpandTemplates para MediaWiki, cuando $wgRawHTML está configurado a verdad, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro wpInpu... • http://www.openwall.com/lists/oss-security/2014/12/21/2 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9479 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9479
16 Jan 2015 — Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via the text parameter to Special:TemplateSandbox. Vulnerabilidad de XSS en la previsualización en la extensión TemplateSandbox para MediaWiki permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro text en Special:TemplateSandbox. Multiple vulnerabilities have been found in MediaWiki, the worst... • http://www.openwall.com/lists/oss-security/2014/12/21/2 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9480 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9480
16 Jan 2015 — Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors related to text extracts. Vulnerabilidad de XSS en la extensión Hovercards para MediaWiki permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores relacionados con extractos de textos. Multiple vulnerabilities have been found in MediaWiki, the worst of which may allow remote attackers to execute arbitrary ... • http://www.openwall.com/lists/oss-security/2014/12/21/2 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9475 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9475
16 Jan 2015 — Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated users to inject arbitrary web script or HTML via a wikitext message. Vulnerabilidad de XSS en thumb.php en MediaWiki anterior a 1.19.23, 1.2x anterior a 1.22.15, 1.23.x anterior a 1.23.8, y 1.24.x anterior a 1.24.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de un mensaje ... • http://www.debian.org/security/2014/dsa-3110 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9476 – Gentoo Linux Security Advisory 201502-04
https://notcve.org/view.php?id=CVE-2014-9476
16 Jan 2015 — MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/." MediaWiki 1.2x anterior a 1.22.15, 1.23.x anterior a 1.23.8, y 1.24.x anterior a 1.24.1 permite a atacantes remotos evadir las restricciones CORS en $wgCrossSiteAJAXdomains a través de un dominio que tiene una coincidencia parcial ... • http://www.mandriva.com/security/advisories?name=MDVSA-2015:006 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2011-0047
https://notcve.org/view.php?id=CVE-2011-0047
04 Feb 2011 — Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability." Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en MediaWiki anterior a v1.16.2, permite a atacantes remotos inyectar secuencias de comandos web o HTML mediante una hoja de estilos (CSS) manipulada, también conocido como "vulnerabilidad de inyección de... • http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2011-0003
https://notcve.org/view.php?id=CVE-2011-0003
11 Jan 2011 — MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors. MediaWiki anterior a v1.16.1, cuando el usuario o el sitio JavaScript o CSS está activado, permite a atacantes remotos realizar ataques de clickjacking a través de vectores no especificados. • http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html • CWE-20: Improper Input Validation •

CVE-2005-1888
https://notcve.org/view.php?id=CVE-2005-1888
06 Jun 2005 — Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates. • http://sourceforge.net/project/shownotes.php?release_id=332231 •