Junglewise Threat Intelligence

CVE-2025-10354: Semantic MediaWiki reflected XSS in GefacetteerdZoeken endpoint

CVE-2025-10354 · Severity: info · CVSS 5.1 · Published 2026-04-21

Technologies: Semantic MediaWiki. Vendors: Semantic MediaWiki.

Executive brief

Semantic MediaWiki is an extension for the MediaWiki software that allows users to manage and query data within wiki pages. A security flaw in this extension allows an attacker to trick a user into clicking a malicious link, which then executes unauthorized code in the user's web browser. This could lead to the theft of login cookies or allow the attacker to perform actions as the victimized user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Semantic MediaWiki versions prior to 5.0.2. The flaw is located in the '/index.php/Speciaal:GefacetteerdZoeken' endpoint, where user-supplied input is improperly neutralized before being rendered in the web page. An unauthenticated remote attacker can exploit this by crafting a malicious URL and enticing a user to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized data access. The issue has been patched in version 5.0.2.

Affected products

  • Semantic MediaWiki Semantic MediaWiki versions prior to 5.0.2

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory
  • 2026-04-21: patched: Fixed in version 5.0.2

References

Related threats