Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
{ "versions": [ { "introduced": "1.30.0" }, { "fixed": "1.30.2" }, { "introduced": "1.31.0" }, { "fixed": "1.31.2" }, { "introduced": "1.32.0" }, { "fixed": "1.32.2" } ] }
[ { "events": [ { "introduced": "0" }, { "last_affected": "9.0" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12471.json"