mediawiki/semantic-media-wiki Security Advisories for 3.1.0-rc.1 (8)
-
[HIGH] Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
PKSA-8k3f-637m-ptt7 GHSA-jr78-w6w5-m8f8
Affected version: >=3.0.0,<=7.2.1
Reported by:
GitHub -
[MEDIUM] Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)
PKSA-5kcn-7vbr-1pdw CVE-2026-77610 GHSA-q5fm-9mx6-44f4
Affected version: <=7.1.0
Reported by:
GitHub -
[MEDIUM] Semantic MediaWiki has an open redirect in Special:URIResolver
PKSA-k3v8-z9j2-2f38 CVE-2026-77609 GHSA-hw3m-8j5x-94ff
Affected version: <=7.1.0
Reported by:
GitHub -
[MEDIUM] Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
PKSA-stqx-crkb-215f CVE-2026-77607 GHSA-7xv3-gf2g-498h
Affected version: <=7.1.0
Reported by:
GitHub -
[MEDIUM] Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
PKSA-2trz-n7bz-xg2h CVE-2026-77608 GHSA-59xw-qv23-j3rc
Affected version: <=7.1.0
Reported by:
GitHub -
[MEDIUM] Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
PKSA-6xyn-p8dg-1kgj CVE-2026-77606 GHSA-3jp5-3h47-28qf
Affected version: <=7.1.0
Reported by:
GitHub -
[HIGH] Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
PKSA-q8ty-xz99-jhhj CVE-2025-61682 GHSA-hg8h-557g-q8pp
Affected version: >=3.1.0,<7.0.0
Reported by:
GitHub -
[MEDIUM] Cross-site Scripting in Semantic MediaWiki
PKSA-t71x-qf1n-7xwy CVE-2022-48614 GHSA-hj4c-vfc4-5f9c
Affected version: <4.0.2
Reported by:
GitHub, FriendsOfPHP/security-advisories