CVE-2025-61682
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
| CWE | CWE-79 |
| Vendor | semanticmediawiki |
| Product | semanticmediawiki |
| Published | Sep 18, 2026 |
| Last Updated | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for semanticmediawiki semanticmediawiki
Be the first to know when new high vulnerabilities affecting semanticmediawiki semanticmediawiki are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low
Affected Versions
SemanticMediaWiki / SemanticMediaWiki
>= 3.1.0, < 7.0.0