Known Vulnerabilities for Timeline by Wikimedia Foundation

Listed below are 10 of the newest known vulnerabilities associated with "Timeline" by "Wikimedia Foundation".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-81820 json Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * objec... Not Provided 2026-08-27 2026-08-27
CVE-2026-74418 json In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepoint null pointer derefer... Not Provided 2026-08-15 2026-08-17
CVE-2026-69079 json CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint.... Not Provided 2026-08-03 2026-08-03
CVE-2026-68383 json In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Keep scheduler timeline name alive The sche... Not Provided 2026-08-10 2026-08-17
CVE-2026-58038 json Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Founda... Not Provided 2026-07-01 2026-07-01
CVE-2026-53056 json In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: fix mismatch between power and frequency D... Not Provided 2026-06-24 2026-06-24
CVE-2026-30279 json An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite ... Not Provided 2026-03-31 2026-07-05
CVE-2026-25699 json Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache ... Not Provided 2026-06-09 2026-06-09
CVE-2026-16063 json The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content s... Not Provided 2026-08-02 2026-08-03
CVE-2026-11943 json Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoic... Not Provided 2026-06-22 2026-06-22

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report