Input Validation Flaw in Wikimedia Foundation's UrlShortener
CVE-2026-13706

NONE

Key Information:

Vendor
CVE Published:
1 July 2026

What is CVE-2026-13706?

An improper input validation vulnerability in the UrlShortener component of the Wikimedia Foundation exposes the application to potential security risks. This flaw exists in the includes/UrlShortenerUtils.php file, where insufficient validation of user input can lead to unexpected behaviors or misuse. It is essential for users and developers to address this vulnerability promptly to maintain the integrity of their applications.

Affected Version(s)

UrlShortener * <= 1.46.0, 1.45.4, 1.44.6, 1.43.9

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.