HTML Injection Vulnerability in Semantic MediaWiki by Semantic MediaWiki
CVE-2026-77607
6.1MEDIUM
What is CVE-2026-77607?
Semantic MediaWiki, an open-source extension for MediaWiki, has a vulnerability that allows for HTML injection due to improper handling of the 'sep' parameter in HTML cell joins. Attackers could exploit this flaw, stemming from versions prior to 7.2.0, to inject arbitrary HTML into wiki pages, potentially compromising the security and integrity of affected installations. The issue has been addressed in version 7.2.0, which implements appropriate sanitization of the separator value, enhancing security and protecting against such injections.
Affected Version(s)
SemanticMediaWiki < 7.2.0
