CVE Feed

    Dashboard / CVE / CVE-2026-33541

    CVE-2026-33541

    TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 34, a flaw in TSPortal allowed attackers to create arbitrary user records in the database by abusing validation logic. While validation correctly rejected invalid usernames, a side effect within a validation rule caused user records to be created regardless of whether the request succeeded. This could be exploited to cause uncontrolled database growth, leading to a potential denial of service (DoS). Version 34 contains a fix for the issue.

    Published:Mar 26, 2026
    Last Modified:Apr 7, 2026
    EPS:Mar 26, 2026
    EPSS Score:0.00049
    CVSS Score:6.5

    Affected Products

    Vendor
    Miraheze
    Product
    Tsportal
    Vendor
    Wikitide
    Product
    Tsportal

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High