CVE-2026-77606
EUVD-2026-8317118.09.2026, 17:17
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version 7.2.0 fixes the issue.
Awaiting analysis
This vulnerability is currently awaiting analysis.