CVE-2013-4567: Mediawiki

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS.

Affected products

  • Mediawiki Mediawiki: up to and including 1.19.8; version 1.19 only; version 1.19.0 only; version 1.19.1 only; version 1.19.2 only; version 1.19.3 only; …

Published 2013-12-13. Last modified 2026-06-16.