Reflected XSS Vulnerability in Semantic MediaWiki Prior to Version 7.2.0
CVE-2026-77610

6.1MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-77610?

The vulnerability in Semantic MediaWiki allows attackers to exploit reflected XSS due to raw HTML being emitted without sufficient output-context encoding. The issue arises when user-supplied query input is echoed back into the response, particularly through query debug output on the Special:Ask page. This happens without requiring special user permissions, allowing any anonymous user to potentially execute malicious scripts through carefully crafted queries that target certain text properties. Version 7.2.0 addresses this vulnerability.

Affected Version(s)

SemanticMediaWiki < 7.2.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.