Scratch Wiki maintains a narrow portfolio of authentication and account-management components for the Scratch educational platform, a widely used programming environment for students. The disclosed vulnerabilities center on these authentication pathways, including the login mechanism, account confirmation flow, and signature validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scratch Wiki over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15164CRITICAL in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those | Aug 28, 2020 | 10.0 | 24 | NO | NO |
CVE-2020-15179CRITICAL The ScratchSig extension for MediaWiki before version 1.0.1 allows stored Cross-Site Scripting. Using <script> tag inside <scratchsig> tag, attackers with edit permission can execu | Sep 15, 2020 | 9.0 | 22 | NO | NO |
CVE-2022-42985MEDIUM The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting | Nov 17, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-46252MEDIUM A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses. | Feb 15, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scratch Wiki.
Media articles that mention a CVE ID that affects a product developed by Scratch Wiki — matched by CVE ID, not by vendor name.