PT-2026-54907 · Wikimedia Foundation · Time-Line-

CVE-2026-58038

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wikimedia Foundation timeline versions prior to 1.46.0 Wikimedia Foundation timeline version 1.45.4 Wikimedia Foundation timeline version 1.44.6 Wikimedia Foundation timeline version 1.43.9
Description Improper neutralization of input during web page generation leads to stored Cross-site Scripting (XSS), where malicious scripts are injected into web pages. This issue occurs through javascript URLs in SVGs generated by the EasyTimeline script and is associated with the files includes/Timeline.Php and scripts/EasyTimeline.Pl.
Recommendations Update to version 1.46.0 or later. Update to a version newer than 1.45.4. Update to a version newer than 1.44.6. Update to a version newer than 1.43.9.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58038

Affected Products

Time-Line-