The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29904.json"