CVE-2020-27621

The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.


We have discovered 7,918 live websites that are affected by CVE-2020-27621.

Test my site




Affected Software

Product  MediaWiki
Category Wikis
Vulnerable Domains7,918 live websites (43.62% of MediaWiki install base)
Vulnerable Versions
  • from 0 through 1.35
Vulnerable Versions Count172 versions ( 73.50% of all versions)



Details

  • Published - Oct 22, 2020
  • Updated - Aug 4, 2024

CVE-2020-27621 usage by Country

United States2,908 websites



Germany1,558 websites
France583 websites
Russia521 websites
Netherlands216 websites
Singapore194 websites
GB176 websites
Switzerland115 websites
Canada108 websites

CVE-2020-27621 usage by TLD

.com1,915 websites
.org1,711 websites
.de727 websites
.net649 websites
.ru420 websites
.info207 websites
.fr148 websites
.eu129 websites
.nl125 websites
.edu84 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-27621

Top websites that are affected by CVE-2020-27621. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
****.********.org United States*,***
*******.com United States*,***
****.***************.org United States**,***
**.************.com United States**,***
****.*******.org Canada**,***
****.*********.org United States**,***
****.********.org Germany**,***
******.org United States**,***
******************.org Germany**,***
See full domain list

FAQ

A total of 7,918 websites have been identified as vulnerable to CVE-2020-27621, discovered through global website indexing conducted by WebTechSurvey.
MediaWiki is susceptible to CVE-2020-27621 vulnerability.
MediaWiki versions before, and including, 1.35 are vulnerable to CVE-2020-27621.