PT-2026-95517 · Unknown · Semantic Mediawiki

CVE-2026-77610

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Semantic MediaWiki versions prior to 7.2.0
Description Semantic MediaWiki contains a reflected Cross-Site Scripting (XSS) issue where query debug output is emitted as raw HTML without proper output-context encoding. This occurs when using the format=debug parameter or the debug request parameter on the Special:Ask endpoint. The SMWQueryDebugFormatter assembles the output, and several sinks fail to escape attacker-controlled input. Specifically, the buildHTML() function echoes the re-serialized ASK query string, and the prettifySQL() and prettifyExplain() functions return SQL and EXPLAIN output verbatim, allowing markup in value literals to survive.
On the Special:Ask endpoint, the resulting string is processed via OutputPage::addHTML, bypassing the MediaWiki parser and Sanitizer. This allows an anonymous user to execute a reflected XSS attack by targeting a text or blob-typed property, such as the predefined txt properties.
Recommendations Update Semantic MediaWiki to version 7.2.0. As a temporary mitigation, restrict access to the Special:Ask endpoint or avoid using the debug parameter until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77610
GHSA-Q5FM-9MX6-44F4

Affected Products

Semantic Mediawiki