Vulnerability Description
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been patched in version 30.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wikitide | Tsportal | < 30 |
Related Weaknesses (CWE)
References
- https://github.com/miraheze/TSPortal/security/advisories/GHSA-gfhq-7499-f3f2ExploitVendor Advisory
- https://issue-tracker.miraheze.org/T15053Issue Tracking
FAQ
What is CVE-2026-29788?
CVE-2026-29788 is a vulnerability with a CVSS score of 7.5 (HIGH). TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty st...
How severe is CVE-2026-29788?
CVE-2026-29788 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29788?
Check the references section above for vendor advisories and patch information. Affected products include: Wikitide Tsportal.