CVE-2026-8857: Full RCE using EasyTimeline Extension
Published Jul 1, 2026
·Updated
A vulnerability in Wikimedia Foundation timeline.
This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php.
This issue affects timeline: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
4 affected components
Wikimedia Foundation timeline>1.43.9<1.46.0
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
Event History
Jul 1, 2026
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 11, 58531
Event
via FIRST·05:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8857?
The severity of CVE-2026-8857 is rated as low with a CVSS score of 4.0.
2
How do I fix CVE-2026-8857?
To fix CVE-2026-8857, update the Wikimedia Foundation timeline to version 1.46.0 or later.
3
What type of vulnerability is CVE-2026-8857?
CVE-2026-8857 is a code injection vulnerability found in the EasyTimeline extension.
4
Which versions are affected by CVE-2026-8857?
The affected versions in CVE-2026-8857 are prior to 1.46.0, specifically 1.45.4, 1.44.6, and 1.43.9.
5
What software is affected by CVE-2026-8857?
CVE-2026-8857 affects the Wikimedia Foundation timeline software.