CVE-2026-77606: Semanticmediawiki
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.2.0 fixes the issue.
Affected products
- Semanticmediawiki Semanticmediawiki: before 7.2.0 (fixed in 7.2.0)
Published 2026-09-18. Last modified 2026-09-24.