CVE-2013-6453: Mediawiki
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.
Affected products
- Mediawiki Mediawiki: version 1.22.0 only; version 1.21 only; version 1.21.1 only; version 1.21.2 only; version 1.21.3 only; up to and including 1.19.9; …
Published 2014-05-12. Last modified 2026-06-17.