| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3jp5-3h47-28qf | Semantic MediaWiki has reflected XSS in Special:Ask plain table headers |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Semantic-mediawiki
Semantic-mediawiki semantic Mediawiki |
|
| Vendors & Products |
Semantic-mediawiki
Semantic-mediawiki semantic Mediawiki |
Fri, 18 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.2.0 fixes the issue. | |
| Title | Semantic MediaWiki has reflected XSS in Special:Ask plain table headers | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T14:59:11.461Z
Reserved: 2026-08-20T20:48:20.507Z
Link: CVE-2026-77606
Updated: 2026-09-22T14:59:04.334Z
Status : Received
Published: 2026-09-18T17:17:00.837
Modified: 2026-09-22T16:17:55.093
Link: CVE-2026-77606
No data.
OpenCVE Enrichment
Updated: 2026-09-21T19:15:17Z
Github GHSA