VDB
GCVE-110-MAGEIA-2014-506
GCVE-110-MAGEIA-2014-506
Advisory Published
In MediaWiki before 1.23.7, a missing CSRF check could allow reflected XSS
on wikis that allow raw HTML (CVE-2014-9276).
MediaWiki's <cross-domain-policy> mangling, in MediaWiki before 1.23.7,
could allow an article editor to inject code into API consumers that blindly
unserialize PHP representations of the page from the API (CVE-2014-9277).
This update provides MediaWiki 1.23.7, which fixes these security issues and
other bugs.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | mediawiki | 0 (affected), 1.23.7-1.mga4 (unaffected) | — |
Aliases
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.