CVE-2020-10960
PHP vulnerability analysis and mitigation

Overview

CVE-2020-10960 affects MediaWiki before version 1.34.1, where users could add various Cascading Style Sheets (CSS) classes which could affect what content is shown or hidden in the application. The vulnerability was discovered and disclosed in March 2020, with patches released as part of MediaWiki versions 1.31.7, 1.33.3, and 1.34.1 (MediaWiki Release).

Technical details

The vulnerability allowed users to manipulate CSS classes that control content visibility within MediaWiki installations. This could potentially lead to unauthorized control over content display and hiding mechanisms in the application. The issue was addressed in the security maintenance release of MediaWiki 1.34.1, along with other versions including 1.31.7 and 1.33.3 (MediaWiki Release).

Impact

The vulnerability could allow attackers to manipulate content visibility through CSS class manipulation, potentially affecting the display or hiding of content in MediaWiki installations. This could lead to unauthorized control over content presentation and potentially impact the integrity of wiki page displays (MediaWiki Release).

Mitigation and workarounds

The vulnerability was patched in MediaWiki versions 1.31.7, 1.33.3, and 1.34.1. Users were advised to upgrade to these versions to address the security issue. The developers noted that due to the minor nature of the vulnerability, immediate patching was not critical if organizations were unable to update immediately (MediaWiki Release).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23622HIGH8.7
  • PHPPHP
  • alextselegidis/easyappointments
NoNoJan 15, 2026
CVE-2025-14894HIGH7.5
  • PHPPHP
  • livewire-filemanager/filemanager
NoNoJan 16, 2026
CVE-2026-23626MEDIUM6.8
  • PHPPHP
  • kimai/kimai
NoYesJan 18, 2026
CVE-2025-69198MEDIUM6
  • PHPPHP
  • pterodactyl/panel
NoYesJan 19, 2026
CVE-2026-23496MEDIUM5.4
  • PHPPHP
  • pimcore/web2print-tools-bundle
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management