THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9rcc-pmj8-ffhr (medium) — Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

[GHSA] GHSA-9rcc-pmj8-ffhr (medium) — Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

highgithub_advisoriesPublished 2026-09-18

GHSA-9rcc-pmj8-ffhr Severity: medium CVE: None

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

### Summary

Special:FacetedSearch `cstate` hidden inputs enable reflected XSS (residual of CVE-2025-10354)

### Details

#### Affected versions and vulnerable location

- Confirmed present on latest shipped release tag available in the

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9rcc-pmj8-ffhr