{"id":"CVE-2025-61682","published":"2026-09-18T16:17:03.717","lastModified":"2026-09-24T21:22:19.873","description":"Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.","cvssScore":8.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.0.0","tags":[]},{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hg8h-557g-q8pp","tags":[]},{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hg8h-557g-q8pp","tags":[]}],"exploitRefs":[{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.0.0","tags":[]},{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hg8h-557g-q8pp","tags":[]},{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hg8h-557g-q8pp","tags":[]}],"hasPoc":true,"ai":null}