In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*" ] }
"https://github.com/bitnami/vulndb/tree/main/data/mediawiki/BIT-mediawiki-2021-45474.json"