Description
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Semantic MediaWiki, an open‑source extension for MediaWiki, contains a reflected cross‑site scripting flaw in the Special:SearchByProperty page. The vulnerability arises when the "value" parameter is reflected back into rendered output and error messages without adequate output‑context encoding. An attacker can inject malicious JavaScript via a crafted URL, allowing arbitrary script execution in the victim’s browser. The weakness aligns with CWE‑79.

Affected Systems

The flaw affects any MediaWiki instance that installs Semantic MediaWiki versions earlier than 7.2.0. Systems that expose the "property" and "value" query parameters on the Special:SearchByProperty page are vulnerable. The vulnerable products include the Semantic MediaWiki extension for MediaWiki across all releases before 7.2.0.

Risk and Exploitability

The CVSS score of 6.1 rates the issue as medium severity. EPSS is unavailable and the vulnerability is not listed in CISA’s KEV catalog, so no evidence of active exploitation in the wild exists. Nevertheless, an attacker could entrap users with a malicious link, resulting in theft of credentials or defacement. The attack vector is primarily through crafted URLs that a victim follows, making the risk user‑centric and mitigable by applying the vendor’s patch or disabling the vulnerable functionality.

Generated by OpenCVE AI on September 19, 2026 at 12:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Semantic MediaWiki to version 7.2.0 or later to apply the vendor fix for reflected XSS.
  • If an upgrade is not yet possible, disable or restrict the Special:SearchByProperty page for untrusted users until the patch can be applied.
  • Account for any custom code that uses the "value" parameter: apply proper output escaping or enforce a content‑security‑policy to mitigate script injection.
  • Monitor logs for requests containing suspicious "value" query parameters and block or quarantine them.

Generated by OpenCVE AI on September 19, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-59xw-qv23-j3rc Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Semantic-mediawiki
Semantic-mediawiki semantic Mediawiki
Vendors & Products Semantic-mediawiki
Semantic-mediawiki semantic Mediawiki

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, whenthe `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue. Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue.

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, whenthe `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue.
Title Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Semantic-mediawiki Semantic Mediawiki
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:49:46.468Z

Reserved: 2026-08-20T20:48:20.508Z

Link: CVE-2026-77608

cve-icon Vulnrichment

Updated: 2026-09-18T19:30:36.247Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:17:01.127

Modified: 2026-09-24T21:22:19.873

Link: CVE-2026-77608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')