Description
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin Events Manager Extended 'admin.php' SQL Injection (3.1.2)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.17)
WordPress Plugin My Calendar Multiple Cross-Site Scripting Vulnerabilities (2.3.9)
WordPress Plugin Booking Calendar Contact Form Multiple Vulnerabilities (1.0.23)
WordPress Plugin All 404 Redirect to Homepage Cross-Site Scripting (1.20)