Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value.
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SemanticMediaWiki | SemanticMediaWiki | < 7.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-61682 | 8.6 HIGH | Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reser |
| CVE-2026-77606 | 6.1 MEDIUM | Semantic MediaWiki has reflected XSS in Special:Ask plain table headers |
| CVE-2026-77609 | 6.1 MEDIUM | Semantic MediaWiki has an open redirect in Special:URIResolver |
| CVE-2026-77608 | 6.1 MEDIUM | Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` |
| CVE-2026-77616 | 6.1 MEDIUM | Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor paginati |
| CVE-2026-77610 | 6.1 MEDIUM | Semantic MediaWiki has a query debug output XSS (`DebugFormatter`) |
No comments yet