CVE-2026-13706: UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG
Published Jul 1, 2026
·Updated
Improper input validation vulnerability in Wikimedia Foundation UrlShortener.
This vulnerability is associated with program files includes/UrlShortenerUtils.Php.
Affected Software
5 affected components
Wikimedia Foundation UrlShortener extension
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13706?
The severity of CVE-2026-13706 is classified as low with a CVSS score of 4.0.
2
How do I fix CVE-2026-13706?
To fix CVE-2026-13706, ensure that the UrlShortener extension is updated to the latest version that addresses the input validation issue.
3
What type of vulnerability is CVE-2026-13706?
CVE-2026-13706 is categorized as an improper input validation vulnerability.
4
Which software is affected by CVE-2026-13706?
CVE-2026-13706 affects the MediaWiki and Wikimedia Foundation UrlShortener extension.
5
When was CVE-2026-13706 published?
CVE-2026-13706 was published on July 1, 2026.