HTML Injection Vulnerability in Semantic MediaWiki by Semantic MediaWiki
CVE-2026-77607

6.1MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-77607?

Semantic MediaWiki, an open-source extension for MediaWiki, has a vulnerability that allows for HTML injection due to improper handling of the 'sep' parameter in HTML cell joins. Attackers could exploit this flaw, stemming from versions prior to 7.2.0, to inject arbitrary HTML into wiki pages, potentially compromising the security and integrity of affected installations. The issue has been addressed in version 7.2.0, which implements appropriate sanitization of the separator value, enhancing security and protecting against such injections.

Affected Version(s)

SemanticMediaWiki < 7.2.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.