Description
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.2.0 fixes the issue.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an attacker to insert arbitrary script into table headers rendered by Semantic MediaWiki when the headers parameter is set to plain. By supplying malicious content in the user‑controlled mainlabel field, the application emits this content directly into a <th> element, leading to client‑side execution for anyone viewing the page. The flaw is a classic reflected XSS type weakness, identified as CWE‑79, which can undermine confidentiality and integrity by executing malicious JavaScript in the victim’s browser.

Affected Systems

Semantic MediaWiki, the open‑source MediaWiki extension, is affected in all releases prior to 7.2.0. Any installation that uses the headers=plain rendering mode and accepts user‑supplied mainlabel data is vulnerable. The fix is available in version 7.2.0 and later.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate risk, and the EPSS score is not available, making the exploitation likelihood difficult to quantify. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker constructing a special:ask query that includes a malicious mainlabel value and setting headers=plain; when the page renders, the attacker’s script executes in the context of any user who views the table.

Generated by OpenCVE AI on September 19, 2026 at 12:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Semantic MediaWiki to version 7.2.0 or later.
  • If an immediate upgrade is not possible, disable the headers=plain option or sanitize the mainlabel input to strip harmful markup.
  • Verify all pages that generate tables with the extension do not use the vulnerable rendering path, and apply generic MediaWiki hardening policies to restrict the execution of script tags.

Generated by OpenCVE AI on September 19, 2026 at 12:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3jp5-3h47-28qf Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Semantic-mediawiki
Semantic-mediawiki semantic Mediawiki
Vendors & Products Semantic-mediawiki
Semantic-mediawiki semantic Mediawiki

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.2.0 fixes the issue.
Title Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Semantic-mediawiki Semantic Mediawiki
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:59:11.461Z

Reserved: 2026-08-20T20:48:20.507Z

Link: CVE-2026-77606

cve-icon Vulnrichment

Updated: 2026-09-22T14:59:04.334Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:17:00.837

Modified: 2026-09-24T21:22:19.873

Link: CVE-2026-77606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')