Cross-Site Scripting in Semantic MediaWiki Affecting Open-Source Users
CVE-2026-77608

6.1MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-77608?

The Semantic MediaWiki extension allows users to store and query data within wiki pages. A vulnerability was identified in versions prior to 7.2.0, where user input from the value parameter could be reflected back into the rendered output and error messages without adequate output-context encoding. This oversight can lead to cross-site scripting (XSS) attacks, potentially compromising user data and application integrity. Users are encouraged to upgrade to version 7.2.0, which has addressed this issue and implemented better security measures.

Affected Version(s)

SemanticMediaWiki < 7.2.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.