Description
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.
Remediation
References
Related Vulnerabilities
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.25)
WordPress Plugin WebHotelier for WordPress Cross-Site Scripting (1.5)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.15)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.5)
WordPress Plugin AMP for WP-Accelerated Mobile Pages Security Bypass (0.9.97.19)