CVE-2014-9481: Mediawiki
Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
Affected products
- Mediawiki Mediawiki: before 1.19.23 (fixed in 1.19.23); from 1.19.24, before 1.22.15 (fixed in 1.22.15); from 1.23.0, before 1.23.8 (fixed in 1.23.8); from 1.23.9, before 1.24.1 (fixed in 1.24.1)
Published 2020-01-27. Last modified 2026-06-17.