CVE-2025-61682: Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
The SemanticMediaWiki extension inserts the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-61682 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →