Description
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin Premium Blocks for Gutenberg Unspecified Vulnerability (1.7.4)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2606)
WordPress Plugin Download Monitor Unspecified Vulnerability (1.9.6)
WordPress Plugin Shantz WordPress QOTD Cross-Site Request Forgery (1.2.2)
WordPress Plugin WP Selected Text Sharer Multiple Vulnerabilities (1.0)