🔐 CVE Alert

CVE-2026-29788

UNKNOWN 0.0

TSPortal: Anyone can forge self-deletion requests of any user

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been patched in version 30.

CWE CWE-283 CWE-1287
Vendor miraheze
Product tsportal
Published Mar 6, 2026
Last Updated Mar 9, 2026
Stay Ahead of the Next One

Get instant alerts for miraheze tsportal

Be the first to know when new unknown vulnerabilities affecting miraheze tsportal are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

miraheze / TSPortal
< 30

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/miraheze/TSPortal/security/advisories/GHSA-gfhq-7499-f3f2 issue-tracker.miraheze.org: https://issue-tracker.miraheze.org/T15053