Medium · 5.5 PHP packages GHSA-hg8h-557g-q8pp CVE-2025-61682 PKSA-q8ty-xz99-jhhj GHSA-jr78-w6w5-m8f8
Semantic MediaWiki: Nine Vulnerabilities Including Unauthenticated Stored XSS and Admin-Task Bypass
Nine separate advisories affect the Semantic MediaWiki extension, including a high-severity stored XSS reachable by unauthenticated users, a missing-authorization flaw exposing admin-only maintenance tasks, and seven lower-severity reflected XSS and open-redirect issues. Fixes are available; most issues are resolved in version 7.2.0, one in 7.0.0, and the authorization flaw in 7.3.0.
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- GitHub Advisory Database database 3w ago · view ↗
- Packagist Security Advisories registry 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
AI summary
Semantic MediaWiki, an extension that lets MediaWiki installations store and query structured data, has nine security advisories disclosed together. The set spans a high-severity stored cross-site scripting (XSS) issue, a missing-authorization flaw in an API module, and seven reflected XSS or open-redirect issues of moderate severity. All nine have fixes available from the vendor. Site operators running Semantic MediaWiki should review the affected version ranges below and update promptly, prioritizing the two highest-severity issues.
Overview of the disclosed issues
Nine separate security advisories were published for the Semantic MediaWiki extension. CVE-2025-61682 (GHSA-hg8h-557g-q8pp) is a stored XSS caused by unsanitized insertion of a data attribute value into the DOM as HTML via wikitext (source_item_ids 3821, 4225, 23838). GHSA-jr78-w6w5-m8f8 describes a missing authorization check in the `smwtask` API module, which backs the same maintenance functions as the admin-only `Special:SMWAdmin` interface but enforces no permission check, allowing unauthenticated access to internal database statistics and state-changing maintenance operations (source_item_ids 3829, 4222). The remaining seven advisories are lower-severity reflected XSS or open-redirect issues: a forged cursor pagination token in `Special:Ask` (CVE-2026-77616, source_item_ids 3827, 4220, 23930); unescaped `value`/`property` parameters in `Special:SearchByProperty` (CVE-2026-77608, source_item_ids 3823, 4224, 23927); unescaped query debug output via `DebugFormatter` (CVE-2026-77610, source_item_ids 3826, 4219, 23929); unescaped plain table headers in `Special:Ask` (CVE-2026-77606, source_item_ids 3822, 4223, 23925); an unvalidated redirect target in `Special:URIResolver` (CVE-2026-77609, source_item_ids 3825, 4218, 23928); and an unescaped `sep` parameter used in HTML cell joins on `Special:Ask` (CVE-2026-77607, source_item_ids 3824, 4217, 23926).
Technical root causes
The stored XSS (CVE-2025-61682) stems from inserting a data attribute value directly into the DOM as HTML without sanitization, allowing script execution through wikitext content (source_item_ids 3821, 4225). The authorization bypass (GHSA-jr78-w6w5-m8f8) is caused by the `Task::execute()` method in the API module performing no permission check at all; it only validates a CSRF token, which MediaWiki issues as a fixed, public value to anonymous users, so the token check provides no actual access control (source_item_ids 3829, 4222). The seven reflected XSS and open-redirect issues each stem from attacker-controlled request parameters (cursor tokens, `value`/`property`, debug output, table headers, `sep`, or subpage targets) being emitted into HTML responses or redirect targets without adequate output-context encoding or validation (source_item_ids 3827, 4220, 3823, 4224, 3826, 4219, 3822, 4223, 3825, 4218, 3824, 4217).
Why this matters
The stored XSS (CVE-2025-61682) is the most severe issue: it requires no authentication, no user interaction, and persists in wiki pages, meaning any visitor who views affected content can have script executed in their browser session, with impact to confidentiality, integrity, and availability (CVSS 8.6). The authorization bypass (GHSA-jr78-w6w5-m8f8) allows unauthenticated attackers to read internal database statistics, enumerate internal object IDs, and trigger state-changing maintenance jobs including entity-disposal operations, which can degrade performance and affect the integrity of stored semantic data (CVSS 7.3, source_item_ids 3829, 4222). The seven remaining issues require user interaction (such as clicking a crafted link) and are scoped to reflected content or redirect targets, resulting in lower severity (CVSS 6.1 each), but they can still be used for phishing or session-targeted script execution.
Who is affected
All sites running the Semantic MediaWiki extension for MediaWiki (package `mediawiki/semantic-media-wiki`) within the affected version ranges listed below are exposed, regardless of wiki size, though the practical impact of the data-disclosure issue scales with how populated the wiki's data store is.
Affected versions
CVE-2025-61682: versions from 3.1.0 up to (but not including) 7.0.0 are affected; fixed in 7.0.0 (source_item_ids 3821, 4225). GHSA-jr78-w6w5-m8f8: versions from 3.0.0 through 7.2.1 inclusive are affected; fixed in 7.3.0 (source_item_ids 3829, 4222). CVE-2026-77616: versions 7.0.0 through 7.1.0 inclusive are affected; fixed in 7.2.0 (source_item_ids 3827, 4220). CVE-2026-77608, CVE-2026-77610, CVE-2026-77606, CVE-2026-77609, and CVE-2026-77607: each affects versions from 0 through 7.1.0 inclusive (i.e., all releases up to and including 7.1.0); all are fixed in 7.2.0 (source_item_ids 3823, 4224, 3826, 4219, 3822, 4223, 3825, 4218, 3824, 4217).
Fixes and mitigation
The vendor has released fixed versions for all nine issues. Version 7.0.0 resolves the stored XSS (CVE-2025-61682). Version 7.2.0 resolves six of the reflected XSS and open-redirect issues (CVE-2026-77616, CVE-2026-77608, CVE-2026-77610, CVE-2026-77606, CVE-2026-77609, CVE-2026-77607). Version 7.3.0 resolves the API authorization bypass (GHSA-jr78-w6w5-m8f8). For the authorization bypass specifically, the advisory notes that sites unable to update immediately can apply a local configuration change to disable the `smwtask` API module via `$wgExtensionFunctions` in `LocalSettings.php` as an interim mitigation (source_item_ids 3829, 4222).
Recommended action
Operators of Semantic MediaWiki should upgrade to version 7.3.0 or later, which includes fixes for all nine issues described here. If immediate upgrading is not feasible, prioritize mitigating the authorization bypass by disabling the `smwtask` API module as described in the vendor advisory, and treat the stored XSS issue as urgent given its unauthenticated, no-interaction attack path.
PatchBriefing score
5.5 / 10 · Medium
Official CVSS: 8.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Why this score
The highest patchwire score (5.5) belongs to CVE-2025-61682, a stored XSS with CVSS 8.6 driven by network attack vector, low complexity, no privileges required, and no user interaction, with confidentiality impact rated high and integrity/availability impact rated low. The score additionally reflects unauthenticated remote reachability and no required user interaction, though EPSS data was not available for this item. The missing-authorization issue (GHSA-jr78-w6w5-m8f8) scores 4.8, based on CVSS 7.3 reflecting unauthenticated network access with limited confidentiality, integrity, and availability impact. The remaining seven issues each score 4.0, based on a shared CVSS of 6.1, which reflects network attack vector but requires user interaction and has a changed scope with limited confidentiality and integrity impact and no availability impact. None of the nine issues have confirmed known exploitation, public exploit code, or EPSS-driven score contributions.
Affected versions
- mediawiki/semantic-media-wiki >= 3.1.0, < 7.0.0
- vulnerable
- mediawiki/semantic-media-wiki >=3.1.0,<7.0.0
- vulnerable
- ≥ 7.0.0
- patched
- mediawiki/semantic-media-wiki >= 3.0.0, <= 7.2.1
- vulnerable
- mediawiki/semantic-media-wiki >=3.0.0,<=7.2.1
- vulnerable
- ≥ 7.3.0
- patched
- mediawiki/semantic-media-wiki >= 7.0.0, <= 7.1.0
- vulnerable
- mediawiki/semantic-media-wiki >=7.0.0,<=7.1.0
- vulnerable
- ≥ 7.2.0
- patched
- mediawiki/semantic-media-wiki <= 7.1.0
- vulnerable
- mediawiki/semantic-media-wiki <=7.1.0
- vulnerable
- ≥ 7.2.0
- patched
- mediawiki/semantic-media-wiki <= 7.1.0
- vulnerable
- mediawiki/semantic-media-wiki <=7.1.0
- vulnerable
- ≥ 7.2.0
- patched
- mediawiki/semantic-media-wiki <= 7.1.0
- vulnerable
- mediawiki/semantic-media-wiki <=7.1.0
- vulnerable
- ≥ 7.2.0
- patched
- mediawiki/semantic-media-wiki <= 7.1.0
- vulnerable
- mediawiki/semantic-media-wiki <=7.1.0
- vulnerable
- ≥ 7.2.0
- patched
- mediawiki/semantic-media-wiki <= 7.1.0
- vulnerable
- mediawiki/semantic-media-wiki <=7.1.0
- vulnerable
- ≥ 7.2.0
- patched
Reported fixes
The vendor has released fixed versions for all nine issues. Version 7.0.0 resolves the stored XSS (CVE-2025-61682). Version 7.2.0 resolves six of the reflected XSS and open-redirect issues (CVE-2026-77616, CVE-2026-77608, CVE-2026-77610, CVE-2026-77606, CVE-2026-77609, CVE-2026-77607). Version 7.3.0 resolves the API authorization bypass (GHSA-jr78-w6w5-m8f8). For the authorization bypass specifically, the advisory notes that sites unable to update immediately can apply a local configuration change to disable the `smwtask` API module via `$wgExtensionFunctions` in `LocalSettings.php` as an interim mitigation (source_item_ids 3829, 4222).
How this was built
23 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email