Reflected XSS Vulnerability in Semantic MediaWiki Prior to Version 7.2.0
CVE-2026-77610
6.1MEDIUM
What is CVE-2026-77610?
The vulnerability in Semantic MediaWiki allows attackers to exploit reflected XSS due to raw HTML being emitted without sufficient output-context encoding. The issue arises when user-supplied query input is echoed back into the response, particularly through query debug output on the Special:Ask page. This happens without requiring special user permissions, allowing any anonymous user to potentially execute malicious scripts through carefully crafted queries that target certain text properties. Version 7.2.0 addresses this vulnerability.
Affected Version(s)
SemanticMediaWiki < 7.2.0
