External risk intelligence

Mediawiki EasyTimeline Extension XML Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-103044

The vulnerability affects a MediaWiki extension, which is typically deployed within web applications that are publicly accessible. Since these extensions are often integrated into public-facing wikis to render content, they are frequently reachable via the internet as part of the web server's request processing surface.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves an XML injection vulnerability within a MediaWiki extension used for creating timelines. Because this extension can be publicly accessible as part of a web application, the vulnerability could potentially allow for unauthorized access and manipulation of data or system functions. The primary concern at this stage is to confirm if this specific extension is in use and exposed.

  • XML injection in timeline extension.
  • Publicly accessible web applications could be at risk.
  • Confirm usage and exposure of the timeline extension.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input to a web application using the EasyTimeline extension. This input would target the extension's handling of XML data, potentially allowing the attacker to inject malicious XML, leading to severe consequences for the application.

  • No authentication needed to start.
  • Triggered by submitting malicious XML input.
  • High impact on confidentiality, integrity, and availability.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, XML injection in the EasyTimeline extension could impact the confidentiality, integrity, and availability of the system by allowing attackers to modify XML syntax and commands before processing. This could lead to unintended service behavior or information disclosure.

  • System data confidentiality and integrity.
  • Malicious XML input injection.
  • Service disruption or unauthorized data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the vulnerability in a MediaWiki extension, the Wikimedia Foundation's platform or application support teams are likely responsible for its management and remediation. The immediate first step is to identify all instances of the EasyTimeline extension within the organization's MediaWiki deployments, assess their reachability and business criticality, and then assign ownership to the accountable team for planning the necessary updates or mitigation strategies.

  • Platform or application support teams own this.
  • Verify EasyTimeline extension deployment and reachability.
  • Plan mitigation or update based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MediaWiki EasyTimeline extension?

EasyTimeline is a specialized extension for the MediaWiki platform, the engine behind sites like Wikipedia. It enables users to render visual timelines directly within wiki pages by processing specific syntax. It is commonly utilized in collaborative environments where editors need to display historical or project-based events graphically.

What does XML injection mean for CVE-2026-103044?

This vulnerability, classified as CWE-91 and CWE-22, occurs when the extension improperly handles user-provided data within XML structures. By injecting malicious XML syntax, an attacker can manipulate how the application interprets data. This can lead to unauthorized access to sensitive information or allow an attacker to disrupt the normal processing functions of the timeline feature.

How is this XML injection flaw triggered?

An attacker triggers this vulnerability by submitting specifically crafted input that the EasyTimeline extension processes as XML data. Because this flaw exists in how the extension parses that input, the attack does not require prior authentication. Simply interacting with the timeline-rendering functionality using malicious data is sufficient to potentially alter the system's behavior.

Is my MediaWiki site at risk if it uses EasyTimeline?

Halo Surface Signal indicates that because EasyTimeline is typically integrated into web applications to render content, these instances are often publicly reachable. If your MediaWiki installation is exposed to the internet to serve content to users, it falls within the likely reach of this vulnerability. Internal-only wikis face lower risk than those accessible to external traffic.

What should I do to address this vulnerability?

Your first step is to inventory all MediaWiki deployments in your environment to identify if the EasyTimeline extension is installed. Once identified, evaluate whether the extension is necessary for your current operations. If it is, verify if you are running a patched version, as the vulnerability affects specific versions prior to 1.46.1, 1.45.5, and 1.43.10.

References