{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-20T00:40:08.708","vulnerabilities":[{"cve":{"id":"CVE-2014-7199","sourceIdentifier":"cve@mitre.org","published":"2014-09-30T14:55:11.827","lastModified":"2025-04-12T10:46:40.837","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file."},{"lang":"es","value":"Vulnerabilidad de XSS en MediaWiki anterior a 1.19.19, 1.22.x anterior a 1.22.11, y 1.23.x anterior a 1.23.4 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un fichero SVG manipulado."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19:*:*:*:*:*:*:*","matchCriteriaId":"93D7105D-3CF1-49FF-9F51-088C58F19003"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19:beta_1:*:*:*:*:*:*","matchCriteriaId":"F647077F-52FD-460B-9511-85812A1447FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19:beta_2:*:*:*:*:*:*","matchCriteriaId":"BB5A8AFF-EF0E-490C-8833-FF1071563979"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.0:*:*:*:*:*:*:*","matchCriteriaId":"A7C29D44-2964-483F-B672-27B5CE471DA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.1:*:*:*:*:*:*:*","matchCriteriaId":"172FEFE5-9900-49D0-9E14-2FA4A7912D23"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.2:*:*:*:*:*:*:*","matchCriteriaId":"CA3205F5-3A29-4D45-AC95-83174F8969BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.3:*:*:*:*:*:*:*","matchCriteriaId":"5547DA02-3BEC-4278-A714-25CCB820AA79"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.4:*:*:*:*:*:*:*","matchCriteriaId":"A3E5609D-EC04-4088-9B61-ABDD256200F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.5:*:*:*:*:*:*:*","matchCriteriaId":"B23B09BB-8F43-4D60-A37F-D8685584AF4B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.6:*:*:*:*:*:*:*","matchCriteriaId":"9A8A3F38-9A86-4346-9337-5C2A1DED37C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.7:*:*:*:*:*:*:*","matchCriteriaId":"49CCC3B5-9BD4-40B4-AF1A-DF4B2A6DC12D"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.8:*:*:*:*:*:*:*","matchCriteriaId":"36DA1112-69AB-408A-886E-F248516FDE11"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.9:*:*:*:*:*:*:*","matchCriteriaId":"DA85F3B7-9CB4-481C-B1A5-AB95F81C4126"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.10:*:*:*:*:*:*:*","matchCriteriaId":"A25C57E2-8E04-4A54-9211-C7B4B7CC4E89"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.11:*:*:*:*:*:*:*","matchCriteriaId":"927A7FCC-273B-4387-A9DB-C1DADB40D3FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.12:*:*:*:*:*:*:*","matchCriteriaId":"37210D17-71E8-4A05-87CE-F27E2F8DDEF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.13:*:*:*:*:*:*:*","matchCriteriaId":"E77B822C-5536-4843-A509-D5471AC02B87"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.14:*:*:*:*:*:*:*","matchCriteriaId":"84198067-1339-4087-9B91-B0AFD45C6F0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.15:*:*:*:*:*:*:*","matchCriteriaId":"5735AFF4-3E99-4E3C-B452-AB9FF31925FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.16:*:*:*:*:*:*:*","matchCriteriaId":"32FCA38F-137E-4CD5-B1EB-44D949468938"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.17:*:*:*:*:*:*:*","matchCriteriaId":"A3099DA6-3F70-4717-92B8-F95DA7EB937B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.19.18:*:*:*:*:*:*:*","matchCriteriaId":"669F2681-6CAC-41A4-BEA3-A2B0B7572D96"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.0:*:*:*:*:*:*:*","matchCriteriaId":"DB117E2F-D4CD-4CED-BCEF-3C821A431F6A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.1:*:*:*:*:*:*:*","matchCriteriaId":"B461B44C-37D2-480B-9645-B7E8720416C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.2:*:*:*:*:*:*:*","matchCriteriaId":"E491E3AD-0FB2-41CD-B852-CAFCA397A45A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.3:*:*:*:*:*:*:*","matchCriteriaId":"CBD50108-A301-4B5B-9047-6FD6792442B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.4:*:*:*:*:*:*:*","matchCriteriaId":"91BBFEC5-A933-4178-919D-9AC87CF76D21"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.5:*:*:*:*:*:*:*","matchCriteriaId":"BD3CA0EC-1AC1-48A1-8BB8-95DCCE1C283A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.6:*:*:*:*:*:*:*","matchCriteriaId":"9343410C-E076-4362-8094-5BA5582E9675"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.7:*:*:*:*:*:*:*","matchCriteriaId":"F96BBB28-AB3C-4082-B035-8CCB761C2530"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.8:*:*:*:*:*:*:*","matchCriteriaId":"7389C3B9-B32D-46CC-8615-22CF7BDCD829"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.9:*:*:*:*:*:*:*","matchCriteriaId":"179FC802-541F-40EE-BB76-A4B745A9EA7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.22.10:*:*:*:*:*:*:*","matchCriteriaId":"3332E0EC-49D6-4EB2-8A2E-CC204EA1C475"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.23.0:*:*:*:*:*:*:*","matchCriteriaId":"6044842D-0C23-4683-9BCC-9FE40AE8353F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.23.1:*:*:*:*:*:*:*","matchCriteriaId":"2BFCBB5A-F5F8-400E-916A-EB87F84853D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.23.2:*:*:*:*:*:*:*","matchCriteriaId":"2898DFC3-7C3A-4C12-A3D2-4CEB3C66C90D"},{"vulnerable":true,"criteria":"cpe:2.3:a:mediawiki:mediawiki:1.23.3:*:*:*:*:*:*:*","matchCriteriaId":"04082771-E3E2-49EE-8840-0170F3B3519F"}]}]}],"references":[{"url":"http://secunia.com/advisories/61666","source":"cve@mitre.org"},{"url":"http://www.debian.org/security/2014/dsa-3036","source":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2014/09/27/2","source":"cve@mitre.org"},{"url":"https://bugzilla.wikimedia.org/show_bug.cgi?id=69008","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://gerrit.wikimedia.org/r/#/c/162777/","source":"cve@mitre.org"},{"url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-September/000161.html","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://secunia.com/advisories/61666","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.debian.org/security/2014/dsa-3036","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2014/09/27/2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.wikimedia.org/show_bug.cgi?id=69008","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://gerrit.wikimedia.org/r/#/c/162777/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-September/000161.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}}]}