Executive brief
A vulnerability exists in the Wikimedia Foundation Timeline extension, which is used to generate graphical timelines on MediaWiki sites. An attacker could potentially inject unauthorized code into the system through the timeline scripts. While the reported severity is low, such issues could theoretically impact the integrity of the content displayed on the platform.
Technical details
A code injection vulnerability (CWE-94) exists in the Wikimedia Foundation Timeline extension, specifically within the scripts/EasyTimeline.pl and includes/Timeline.php files. The vulnerability allows for improper control of the generation of code. The attack vector is network-based and requires low privileges (PR:L), though the reported CVSS 4.0 score is 0.0, suggesting minimal direct impact in its current state. The issue has been addressed in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.
Affected products
- Wikimedia Foundation Timeline extension Before 1.46.0, 1.45.4, 1.44.6, 1.43.9
Timeline
- 2026-07-01: advisory
- 2026-07-01: disclosed