Description In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. Remediation References CVE-2021-45471 Related Vulnerabilities PHP Out-of-bounds Read Vulnerability (CVE-2016-6294) WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Directory Traversal (4.9.9) Python Other Vulnerability (CVE-2012-2135) SharePoint CVE-2020-1295 Vulnerability (CVE-2020-1295) SharePoint Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-47172) Severity Medium Classification CVE-2021-45471 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities