PT-2026-54907 · Wikimedia Foundation · Time-Line-
CVE-2026-58038
·
Published
2026-07-01
·
Updated
2026-07-01
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wikimedia Foundation timeline versions prior to 1.46.0
Wikimedia Foundation timeline version 1.45.4
Wikimedia Foundation timeline version 1.44.6
Wikimedia Foundation timeline version 1.43.9
Description
Improper neutralization of input during web page generation leads to stored Cross-site Scripting (XSS), where malicious scripts are injected into web pages. This issue occurs through javascript URLs in SVGs generated by the
EasyTimeline script and is associated with the files includes/Timeline.Php and scripts/EasyTimeline.Pl.Recommendations
Update to version 1.46.0 or later.
Update to a version newer than 1.45.4.
Update to a version newer than 1.44.6.
Update to a version newer than 1.43.9.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Time-Line-