THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-59xw-qv23-j3rc (medium) — Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)

[GHSA] GHSA-59xw-qv23-j3rc (medium) — Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)

medgithub_advisoriesPublished 2026-09-18

GHSA-59xw-qv23-j3rc Severity: medium CVE: CVE-2026-77608

Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)

#### Failure mode

The `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding.

#### Remediation

- The form value is escaped before it is placed back into the input fiel

Indicators of compromise

Original source: https://github.com/advisories/GHSA-59xw-qv23-j3rc