CVE-2026-103044
N/A
N/A
Summary
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection.
This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The Wikimedia Foundation | Mediawiki - EasyTimeline extension | 0 < 1.46.1, 1.45.5, 1.43.10 | affected |
Weaknesses
- CWE-91: CWE-91 XML injection (aka blind XPath injection)
References
- https://phabricator.wikimedia.org/T428006
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/timeline/+/1346078
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.