Semantic MediaWiki has reflected XSS in Special:Ask plain table headers (CVE-2026-77606) | HOL Guard CVE