{"id":"CVE-2025-61682","title":"Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages","summary":"Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","cwe":["CWE-79"],"vendor":"mediawiki","product":"mediawiki/semantic-media-wiki","affected":["mediawiki/semantic-media-wiki >= 3.1.0, < 7.0.0"],"patched":["mediawiki/semantic-media-wiki 7.0.0"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:04.307","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-61682","references":[{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.0.0","label":"security-advisories@github.com"},{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hg8h-557g-q8pp","label":"security-advisories@github.com"},{"url":"https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-hg8h-557g-q8pp","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-hg8h-557g-q8pp"}],"tags":["nvd","ghsa","composer","cve.org","exploit-available"],"aliases":["GHSA-hg8h-557g-q8pp"],"ecosystem":"composer","exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-18T17:23:36.648760Z"},"ingestedAt":"2026-09-18T16:45:41.378Z","epss":0.00292,"epssPercentile":0.22006,"slug":"CVE-2025-61682","body":"## Overview\n\nSemantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2025-61682)\n\nAffected packages:\n\n- `mediawiki/semantic-media-wiki >= 3.1.0, < 7.0.0`\n\nPatched in:\n\n- `mediawiki/semantic-media-wiki 7.0.0`\n\nSource: https://github.com/advisories/GHSA-hg8h-557g-q8pp","depth":"midnight","depthScore":59,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":207071,"id":"CVE-2025-61682","ts":1789753656283,"field":"exploit_available","old":"false","new":"true"}]}