| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wikimedia Foundation | timeline | *< 1.46.0, 1.45.4, 1.44.6, 1.43.9 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wikimedia Foundation | timeline | * ~ 1.46.0, 1.45.4, 1.44.6, 1.43.9 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | MediaWiki EasyTimeline (Timeline) extension versions before 1.46.0, 1.45.4, 1.44.6, and 1.43.9 contain a code injection vulnerability caused by insufficient neutralization of newlines in TextData text attributes in EasyTimeline.pl / Timeline.php. A crafted <timeline> block can inject ploticus '#proc getdata' and 'command:' directives, which execute via /bin/sh because EasyTimeline invokes ploticus without the -noshell flag. Exploitation requires the ability to submit timeline markup for rendering — low-privileged edit access, or anonymous access on wikis that allow anonymous editing and API use. This template's parse-based check needs API read access; optional username/password inputs can be supplied for private wikis that deny anonymous read. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8857.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-58038 | Stored XSS through javascript URLs in SVGs generated by EasyTimeline | |
| CVE-2026-13706 | UrlShortener extension url validation can be bypassed due to difference between php url pa | |
| CVE-2026-13707 | Session fixation attacks on improperly configured OAuth 1.0a tools | |
| CVE-2026-58034 | Stored XSS through a system message when blocking a temporary account that's related to ot | |
| CVE-2026-58028 | Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets | |
| CVE-2026-58029 | Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata | |
| CVE-2026-58036 | Users API leaks whether privileged users have their user groups disabled for lack of 2FA | |
| CVE-2026-58030 | SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute | |
| CVE-2026-58033 | "Total number of distinct authors" statistic at action=info does not exclude revisions whe | |
| CVE-2026-58037 | Core log entries for exceptions and XSS issues in log entry formatting code that may be ca | |
| CVE-2026-58027 | QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden | |
| CVE-2026-58031 | Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected | |
| CVE-2026-58032 | mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html | |
| CVE-2026-58024 | API identification of users on private wikis | |
| CVE-2026-58025 | Remote Code Execution via Unsafe Deserialization in LogItem Import | |
| CVE-2026-58026 | $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces | |
| CVE-2026-58035 | Stored XSS through a system message in the codex version of Special:Block |
No comments yet