Executive brief
The Wikimedia Foundation Timeline extension, used to generate graphical timelines on MediaWiki sites, contains a security flaw. This vulnerability could allow an attacker to inject malicious scripts into web pages viewed by other users. Such an attack could lead to unauthorized actions being performed in a user's session or the theft of sensitive information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Wikimedia Foundation Timeline extension, specifically within the 'includes/Timeline.php' and 'scripts/EasyTimeline.pl' files. The flaw stems from improper neutralization of user-supplied input during the generation of web pages. An attacker with low privileges could exploit this via the network to inject arbitrary scripts. While the provided CVSS 4.0 score is 0.0, the vulnerability is classified as CWE-79. Patches have been released in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.
Affected products
- Wikimedia Foundation Timeline extension before 1.46.0, 1.45.4, 1.44.6, 1.43.9
Timeline
- 2026-07-01: advisory: Initial disclosure of CVE-2026-58038