Wikimedia Foundation Timeline Vulnerability in EasyTimeline Scripts
CVE-2026-8857

NONE

Key Information:

Status
Vendor
CVE Published:
1 July 2026

What is CVE-2026-8857?

A vulnerability in the Wikimedia Foundation Timeline product affects specific versions of the EasyTimeline scripts. The flaw exists in the program files scripts/EasyTimeline.Pl and includes/Timeline.Php, allowing attackers to potentially manipulate the structure and data presented within the timeline. Users operating versions prior to 1.46.0, as well as 1.45.4, 1.44.6, and 1.43.9, are at risk of exposure to this vulnerability, which could lead to unauthorized information disclosure or modification. Timely updates to the product are advisable to mitigate the risks associated with this issue.

Affected Version(s)

timeline * < 1.46.0, 1.45.4, 1.44.6, 1.43.9

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.