AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-35478

MEDIUM · CVSS 6.1 EPSS 1.35%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-35478
Severity
MEDIUM
CVSS
6.1
EPSS
1.35%

Original NVD Description

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.

Related CVEs

Other vulnerabilities affecting the same vendor(s)