MediaWiki 1.31 (LTS)
MediaWiki 1.31 (LTS)
The MediaWiki 1.31 (LTS) reached end of service life on Sep 30, 2021 — MediaWiki no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your MediaWiki 1.31 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- mediawiki
- release
- 1.31
- product Label
- MediaWiki
- release Label
- 1.31 (LTS)
- codename
- lts
- true
- latest Version
- 1.31.16
- release Date
- 2018-06-13
- maintained
- source Url
- https://endoflife.date/mediawiki
Lifecycle Dates
- End of Service Life
- Sep 30, 2021
- Last OEM Support
- Sep 30, 2021
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for MediaWiki 1.31 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for MediaWiki 1.31 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for MediaWiki 1.31 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
MediaWiki 1.31 (LTS) Support: Frequently Asked Questions
Is the MediaWiki 1.31 (LTS) still supported?
MediaWiki ended support for the MediaWiki 1.31 (LTS) on Sep 30, 2021 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the MediaWiki 1.31 (LTS) end of service life (EOSL) date?
MediaWiki lists the end of service life for the MediaWiki 1.31 (LTS) as Sep 30, 2021.
Can I keep using the MediaWiki 1.31 (LTS) after its EOSL date?
Yes. EOSL means MediaWiki stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the MediaWiki 1.31 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting MediaWiki 1.31 (LTS)
193 published CVEs affect the MediaWiki 1.31 (LTS), including 45 rated critical or high severity. MediaWiki no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-34502 | CRITICAL | 9.8 | May 5, 2024 | An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token. |
| CVE-2023-37303 | CRITICAL | 9.8 | Jun 30, 2023 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message. |
| CVE-2023-29141 | CRITICAL | 9.8 | Mar 31, 2023 | An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header. |
| CVE-2022-29906 | CRITICAL | 9.8 | Apr 29, 2022 | The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user. |
| CVE-2022-29904 | CRITICAL | 9.8 | Apr 29, 2022 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. |
| CVE-2022-28209 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect. |
| CVE-2022-28206 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights. |
| CVE-2022-28205 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future. |
| CVE-2021-31556 | CRITICAL | 9.8 | Aug 12, 2021 | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob. |
| CVE-2021-36128 | CRITICAL | 9.8 | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented. |
| CVE-2021-36126 | CRITICAL | 9.8 | Jul 2, 2021 | An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user. |
| CVE-2020-10534 | CRITICAL | 9.8 | Mar 12, 2020 | In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled. |
| CVE-2019-12468 | CRITICAL | 9.8 | Jul 10, 2019 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover. |
| CVE-2021-46147 | HIGH | 8.8 | Jan 10, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF. |
| CVE-2021-41801 | HIGH | 8.8 | Oct 11, 2021 | The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog) |
| CVE-2021-36132 | HIGH | 8.8 | Jul 2, 2021 | An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform. |
| CVE-2020-29004 | HIGH | 8.8 | Jan 29, 2021 | The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack. |
| CVE-2020-35626 | HIGH | 8.8 | Dec 21, 2020 | An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php. |
| CVE-2020-35625 | HIGH | 8.8 | Dec 21, 2020 | An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty template. For example, a person in the Widget Editors group could use \MediaWiki\Shell\Shell::command within a comment. |
| CVE-2019-12466 | HIGH | 8.8 | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 allows CSRF. |
Showing the 20 most severe of 193 known CVEs.
Get Third Party Support