CVE-2026-29788

HIGH

TSPortal < 30 - Improper Validation of Input

Title source: llm
STIX 2.1

Description

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been patched in version 30.

References (2)

Core 2
Core References
Various Sources x_refsource_misc
https://issue-tracker.miraheze.org/T15053

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1287 CWE-283
Status published
Products (2)
miraheze/ts-portal 0 - 30Packagist
wikitide/tsportal < 30
Published Mar 06, 2026
Tracked Since Mar 07, 2026