CVE-2026-77607: Semanticmediawiki
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value. Version 7.2.0 fixes the issue.
Affected products
- Semanticmediawiki Semanticmediawiki: before 7.2.0 (fixed in 7.2.0)
Published 2026-09-18. Last modified 2026-09-23.