CVE-2023-36675: Mediawiki
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, and 1.39.x before 1.39.4. BlockLogFormatter.php in BlockLogFormatter allows XSS in the partial blocks feature.
Affected products
- Mediawiki Mediawiki: before 1.35.11 (fixed in 1.35.11); from 1.36.0, before 1.38.7 (fixed in 1.38.7); from 1.39.0, before 1.39.4 (fixed in 1.39.4)
Published 2023-06-26. Last modified 2026-06-17.