PT-2026-95499 · Mediawiki · Semantic Mediawiki

CVE-2026-77608

·

Published

2026-09-18

·

Updated

2026-09-27

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Semantic MediaWiki versions prior to 7.2.0
Description Semantic MediaWiki is an open-source extension for MediaWiki used for storing and querying data. The software fails to apply sufficient output-context encoding when the value parameter is reflected in rendered output and error messaging paths. This lack of encoding allows the value parameter to be processed without proper escaping before being placed back into input fields or rendered as HTML in error messages.
Recommendations Update to version 7.2.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77608
GHSA-59XW-QV23-J3RC

Affected Products

Semantic Mediawiki