Description
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Human Resource Management Security Bypass (2.2.14)
WordPress Plugin Pinpoint Booking System-#1 WordPress Booking SQL Injection (1.2)
MySQL CVE-2022-21595 Vulnerability (CVE-2022-21595)
WordPress Plugin Email Queue by BestWebSoft Cross-Site Request Forgery (1.0.0)
Joomla Improper Input Validation Vulnerability (CVE-2021-26036)