Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-10354 1 Semantic-mediawiki 1 Semantic Mediawiki 2026-04-21 N/A
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
CVE-2022-48614 1 Semantic-mediawiki 1 Semantic Mediawiki 2024-11-21 6.1 Medium
Special:Ask in Semantic MediaWiki before 4.0.2 allows Reflected XSS.