📦

widgets

Vendor: widgets_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 1.49% Exploit Prob.
Latest CVE CVE-2020-9382 Feb 24

Security Vulnerability Index

Page 1 / 1
5.4 CVSS

An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

EPSS: 0.97%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content.

EPSS: 2.01%