CVE-2014-9487: Mediawiki
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to CVE-2014-2053.
Affected products
- Mediawiki Mediawiki: version 1.19 only; version 1.19.0 only; version 1.19.1 only; version 1.19.2 only; version 1.19.3 only; version 1.19.4 only; …
Published 2017-10-17. Last modified 2026-06-17.