Home/Product/mediawiki cargo
Product

mediawiki cargo

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39841
< 3.8.7
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Ca
6.1MEDIUM
CVE-2026-39840
< 3.8.7
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawi
6.1MEDIUM
CVE-2026-39839
< 3.8.7
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Ca
6.1MEDIUM
CVE-2026-39837
< 3.8.7
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extensi
5.4MEDIUM
CVE-2024-47849
all versions
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Med
9.8CRITICAL
CVE-2024-47847
all versions
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundat
6.1MEDIUM
CVE-2024-47846
all versions
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.Th
8.8HIGH
CVE-2023-38497
< 0.72.2
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior
7.9HIGH
CVE-2022-46176
<= 0.67.0
Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification w
5.3MEDIUM
CVE-2022-36114
< 0.65.0
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extrac
4.8MEDIUM
CVE-2022-36113
< 0.65.0
Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the
4.6MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin