CVE-2026-77607

Source
https://cve.org/CVERecord?id=CVE-2026-77607
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77607.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77607
Aliases
Published
2026-09-18T16:51:10Z
Modified
2026-09-20T11:47:26Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
Details

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, sep was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value. Version 7.2.0 fixes the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77607.json"
}
References

Affected packages

Git / github.com/semanticmediawiki/semanticmediawiki

Affected ranges

Type
GIT
Repo
https://github.com/semanticmediawiki/semanticmediawiki
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.2.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.6
0.7
1.*
1.0
1.0.1
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.3
1.4
1.4.1
1.4.2
1.4.3
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.6
1.6.1
1.7
1.7.0.1
1.7.0.2
1.7.1
1.8beta1
1.8beta2
1.9
1.9-RC1
1.9.0.1
1.9.0.2
1.9.1
1.9.1.1
1.9.2
1.9beta1
2.*
2.0-RC1
2.0-RC2
2.0-RC3
2.1.0-RC1
2.3.0
2.3.0-RC1
2.4.0
2.4.0-RC1
2.5.0
2.5.0-rc.1
3.*
3.0.0
3.0.0-rc.1
3.0.0-rc.2
3.1.0
3.1.0-rc.1
3.2.0
3.2.0-rc.1
3.2.0-rc.2
4.*
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
5.*
5.0.0
5.0.1
5.0.2
5.1.0
6.*
6.0.0
6.0.1
7.*
7.0.0
7.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77607.json"