CVE-2026-77606 - Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
CVE ID :CVE-2026-77606
Published : Sept. 18, 2026, 4:41 p.m. | 27 minutes ago
Description :Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.2.0 fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 18, 2026, 4:41 p.m. | 27 minutes ago
Description :Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...