Description
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.
Remediation
References
Related Vulnerabilities
WordPress Plugin InPost Gallery Multiple Vulnerabilities (2.1.2)
Roundcube Improper Input Validation Vulnerability (CVE-2011-1492)
PHP Other Vulnerability (CVE-2015-6837)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2082)
WordPress Plugin Abandoned Cart Lite for WooCommerce Security Bypass (5.14.2)