CVE-2015-2935: Mediawiki

Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

Affected products

  • Mediawiki Mediawiki: up to and including 1.19.23; version 1.20 only; version 1.20.1 only; version 1.20.2 only; version 1.20.3 only; version 1.20.4 only; …

Published 2015-04-13. Last modified 2026-06-17.