CVE-2026-77606 - Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
Brief
CVE ID : CVE-2026-77606
Published : Sept. 18, 2026, 4:41 p. m.
- 14 minutes ago
Description : Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.
- 0, when `headers=plain`, table header text was emitted into ` ` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.
- 0 fixes the issue.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
