Previous work: {T292236}
| Maniphest ID | Extension or Skin | CVE ID | REL1_35 | REL1_36 | REL1_37 | master
| ---- | ---- | ---- | ---- | ---- | ---- | --- | --- | ---
| T285116 | [[ https://www.mediawiki.org/wiki/Extension:Echo | Echo ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T298019 | [[ https://www.mediawiki.org/wiki/Extension:GrowthExperiments | GrowthExperiments ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/752763 | Yes ]]
| T298581 | [[ https://www.mediawiki.org/wiki/Extension:MobileFrontend | MobileFrontend ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/751828 | Yes ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/751827 | Yes ]] | [[ https://gerrit.wikimedia.org/r/751811 | Yes ]]
| T298434 | [[ https://www.mediawiki.org/wiki/Extension:SecurePoll | SecurePoll ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T294256 | [[ https://www.mediawiki.org/wiki/Extension:FileImporter | FileImporter ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28206 | CVE-2022-28206 ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/757022 | Yes ]]
| T298312 | [[ https://www.mediawiki.org/wiki/Extension:GrowthExperiments | GrowthExperiments ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28207 | CVE-2022-28207 ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T302248 | [[ https://www.mediawiki.org/wiki/Extension:CentralAuth | CentralAuth ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28205 | CVE-2022-28205 ]] | N/A | N/A | N/A | [[ https://gerrit.wikimedia.org/r/765335 | Yes ]]
| T302215 | [[ https://www.mediawiki.org/wiki/Extension:Wikibase | Wikibase ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28208 | CVE-2022-28208 ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T302192 | [[ https://www.mediawiki.org/wiki/Extension:JsonConfig | JsonConfig ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T160800 | [[ https://www.mediawiki.org/wiki/Extension:TimedMediaHandler | TimedMediaHandler ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T304126 | [[ https://www.mediawiki.org/wiki/Extension:AntiSpoof | AntiSpoof ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | N/A | [[ https://gerrit.wikimedia.org/r/772477 | Yes ]] | [[ https://gerrit.wikimedia.org/r/772476 | Yes ]] | [[ https://gerrit.wikimedia.org/r/772519 | Yes ]]
| T304354 | [[ https://www.mediawiki.org/wiki/Extension:FlaggedRevs | FlaggedRevs ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
| T226212 | [[ https://www.mediawiki.org/wiki/Extension:CentralAuth | CentralAuth ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
**template**
| Txxxxxx | [[ https://www.mediawiki.org/wiki/Extension:ExtName | ExtName ]] | [[ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-yyyyy | CVE-2021-yyyyy ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]] | [[ https://gerrit.wikimedia.org/r/ | No ]]
**n.b.** For the Echo bug, there is an updated patch here: T285116#7585701
**n.b.** Two patches for the JsonConfig issue, should be squashed
**n.b.** Two patches for the CentralAuth issue
**possibly include**: {T302199}