CVE-2014-9276: Mediawiki
Medium severity, CVSS 5.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgRawHTML is set to true, allows remote attackers to hijack the authentication of users with edit permissions for requests that cross-site scripting (XSS) attacks via the wpInput parameter, which is not properly handled in the preview.
Affected products
- Mediawiki Mediawiki: up to and including 1.19.21; version 1.20 only; version 1.20.1 only; version 1.20.2 only; version 1.20.3 only; version 1.20.4 only; …
Published 2015-01-04. Last modified 2026-06-17.