OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103044

CRITICAL · CVSS 9.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The EasyTimeline extension for MediaWiki is vulnerable to XML injection, specifically blind XPath injection, which could allow an attacker to manipulate XML data and potentially execute unauthorized actions. Users of affected versions (prior to 1.46.1, 1.45.5, and 1.43.10) should prioritize patching this vulnerability to mitigate the risk of data compromise and unauthorized access. Organizations utilizing this extension should assess their deployments and apply updates promptly to safeguard their systems.

CVE
CVE-2026-103044
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.