Vulnerability Description
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/SemanticMediaWiki/SemanticMediaWiki/releases/tag/7.0.0
- https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-
- https://github.com/SemanticMediaWiki/SemanticMediaWiki/security/advisories/GHSA-
FAQ
What is CVE-2025-61682?
CVE-2025-61682 is a vulnerability with a CVSS score of 8.6 (HIGH). Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized valu...
How severe is CVE-2025-61682?
CVE-2025-61682 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-61682?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.