CVE-2026-77606: Semantic MediaWiki has reflected XSS in Special:Ask plain table headers

Published Sep 18, 2026
·
Updated

Failure mode

When headers=plain, table header text was emitted into <th> via a raw HTML path. User-controlled mainlabel content could therefore become executable HTML.

Remediation

- TableResultPrinter now applies output-context escaping before passing plain headers to the table renderer. - The fix is limited to the HTML/plain-header branch so safe rendering modes are unaffected.

Why this is the right layer

The header value is not a structural token; it is display data. Sanitizing it at the sink is correct because the renderer owns the final HTML emission.

Other sources

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when headers=plain, table header text was emitted into <th> via a raw HTML path. User-controlled mainlabel content could therefore become executable HTML. Version 7.2.0 fixes the issue.

MITRE

Affected Software

2 affected componentsFixes available
Semantic MediaWiki Semantic MediaWiki<7.2.0
composer/mediawiki/semantic-media-wiki<=7.1.0
7.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/mediawiki/semantic-media-wiki to a version that resolves this vulnerability.

    Fixed in 7.2.0
  2. Upgrade

    Upgrade Semantic MediaWiki to a version that resolves this vulnerability.

    Fixed in 7.2.0

Event History

Sep 18, 2026
Advisory Published
via GitHub·04:40 PM
Data Sourced
via GitHub·04:40 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required for exploitation?

An attacker needs to induce a user to view a Special:Ask result that uses headers=plain and contains attacker-controlled mainlabel content. No attacker privileges are required, but user interaction is required.

2

Are default query configurations affected?

The issue is specifically tied to queries using the headers=plain setting. The provided information does not indicate that other header configurations are affected.

3

What should be done if upgrading cannot happen immediately?

Avoid or remove use of headers=plain in Special:Ask queries, particularly where mainlabel content may be influenced by untrusted users. Upgrade to Semantic MediaWiki 7.2.0 when possible.

4

How can I identify potentially affected content?

Review Special:Ask queries for the headers=plain parameter and check whether their mainlabel value can contain user-controlled text. Versions prior to 7.2.0 are affected under those conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203