CVE-2026-58038: Stored XSS through javascript URLs in SVGs generated by EasyTimeline
Published Jul 1, 2026
·Updated
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline.
This vulnerability is associated with program files includes/Timeline.Php, scripts/EasyTimeline.Pl.
This issue affects timeline: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
5 affected components
Wikimedia Foundation timeline><1.46.0, =1.45.4, =1.44.6, =1.43.9
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58038?
The severity of CVE-2026-58038 is classified as low.
2
How do I fix CVE-2026-58038?
To fix CVE-2026-58038, upgrade the Wikimedia Foundation timeline to version 1.46.0 or later.
3
What type of vulnerability is CVE-2026-58038?
CVE-2026-58038 is a Stored XSS (Cross-site Scripting) vulnerability.
4
Which software is affected by CVE-2026-58038?
CVE-2026-58038 affects the Wikimedia Foundation timeline software.
5
What components are involved in CVE-2026-58038?
CVE-2026-58038 involves the program files includes/Timeline.Php and scripts/EasyTimeline.Pl.