Posted on 2026-09-29

Semantic MediaWiki 7.3 Released

Semantic MediaWiki 7.3.0 and 7.3.1 are out. Both releases improve security, and we recommend that everyone upgrades to 7.3.1.

As maintainers of Semantic MediaWiki (SMW), we are proud to announce versions 7.3.0 and 7.3.1, released on September 16 and September 28, 2026. Both are compatible with MediaWiki 1.43 through 1.46 and PHP 8.1 through 8.5.

Security fixes

Together, the two releases fix 21 security advisories, eight of them rated high. Version 7.3.0 fixed a missing authorization check in the smwtask API module, through which anyone, without logging in, could read internal database statistics and reach maintenance operations meant for administrators. Version 7.3.1 resolves 20 more security advisories, among them twelve cross-site scripting issues across special pages, result formats, tooltips, and autocomplete, a cross-site request forgery in Special:SMWAdmin, a way for ordinary editors to protect pages indefinitely, and four denial-of-service issues. The details are in the published security advisories.

Nineteen of the 21 also affect SMW 5 and 6, and five go back as far as SMW 2.5. Security fixes only go into the latest major version, so if your wiki runs SMW 6 or older, upgrading to SMW 7.3.1 is the way to get them.

Some of the fixes tighten input handling, so requests that previously succeeded may now be rejected, and some HTML that used to render may now show as plain text. If something your wiki depends on stops working after the upgrade, please open an issue.

Also new in 7.3.0

Full-text search no longer ignores short words and stop words that carry a wildcard. A query such as [[Has text::~to* be]] used to search only for "be" and now also finds words starting with "to", so such queries can return more results than before.

The new $smwgConfigProfiles setting applies the configuration profiles that ship with SMW, such as db-primary-keys. See Upgrading if you enabled a profile following the 7.0.0 release notes.

The two releases also fix 12 bugs. Find every change in the release notes of 7.3.0 and 7.3.1.

Use Semantic MediaWiki with AI

You can connect Claude, ChatGPT, and other AI tools to your Semantic MediaWiki via our open source MCP server, and let them run queries or even edit on your behalf. Find out more in Use Semantic MediaWiki with AI.

Credits

Semantic MediaWiki logo

These releases were led by our own Alistair Kim, who implemented the bulk of the security enhancements. We thank the security researchers who reported these issues responsibly, and everyone who contributed.

Semantic MediaWiki is free and community-driven. Please consider donating to Semantic MediaWiki to support its continued development.

Upgrading

From 7.3.0, upgrading to 7.3.1 needs no extra steps. From an earlier SMW 7 version, these steps may apply:

  • If your wiki uses properties of type URL, Annotation URI, or Email, run the rebuildData maintenance script, since queries can otherwise miss some values stored by earlier versions.
  • If you enabled a configuration profile with the require line recommended by the 7.0.0 release notes, that line had no effect. Replace it with $smwgConfigProfiles and run update.php, which the db-primary-keys, elastic-fileingest, and media profiles need. A wiki that loads a profile both ways does not start.
  • If you upgrade from a version before 7.2.1 and use Elasticsearch or OpenSearch, run rebuildElasticIndex --only-update once to correct the sort order.
  • If you upgrade from a version before 7.2.0 and set $smwgEntityCollation to a uca-* value, run updateEntityCollation.php once.

If your wiki runs SMW 6 or older, the upgrade crosses a major version and requires running update.php, among other steps. SMW 7 also requires MediaWiki 1.43 or later, so wikis on an older MediaWiki need to upgrade that as well. Our Semantic MediaWiki 7 release post and the 7.0.0 release notes describe that upgrade, and the list above applies too. Where those notes recommend a require line for a configuration profile, use $smwgConfigProfiles instead. Since 7.2.1, the database conversion that update.php runs for SMW 7 works in batches and resumes where an interrupted run stopped, which helps on large wikis.

See the upgrading sections of the release notes for the exact commands, and the Semantic MediaWiki 7.3.1 release page for an overview.

Professional Semantic MediaWiki Services

At Professional Wiki, we provide Semantic MediaWiki services, including SMW hosting, SMW software development, SMW consulting, and MediaWiki upgrades. If you would rather not upgrade your wiki yourself, we can do it for you.

Request a wiki with Semantic MediaWiki and it is typically ready within 2 business days.