Cross-Site Scripting in Semantic MediaWiki Affecting Open-Source Users
CVE-2026-77608
6.1MEDIUM
What is CVE-2026-77608?
The Semantic MediaWiki extension allows users to store and query data within wiki pages. A vulnerability was identified in versions prior to 7.2.0, where user input from the value parameter could be reflected back into the rendered output and error messages without adequate output-context encoding. This oversight can lead to cross-site scripting (XSS) attacks, potentially compromising user data and application integrity. Users are encouraged to upgrade to version 7.2.0, which has addressed this issue and implemented better security measures.
Affected Version(s)
SemanticMediaWiki < 7.2.0
