Semantic MediaWiki 7.3 Released
Semantic MediaWiki 7.3.0 and 7.3.1 are out. Both releases improve security, and we recommend that everyone upgrades to 7.3.1.
As maintainers of Semantic MediaWiki (SMW), we are proud to announce versions 7.3.0 and 7.3.1, released on September 16 and September 28, 2026. Both are compatible with MediaWiki 1.43 through 1.46 and PHP 8.1 through 8.5.
Security fixes
Together, the two releases fix 21 security advisories, eight of them rated high. Version 7.3.0 fixed a missing
authorization check in the smwtask API module, through which anyone, without logging in, could read
internal database statistics and reach maintenance operations meant for administrators. Version 7.3.1 resolves 20
more security advisories, among them twelve cross-site scripting issues across special pages, result formats,
tooltips, and autocomplete, a cross-site request forgery in Special:SMWAdmin, a way for ordinary editors
to protect pages indefinitely, and four denial-of-service issues. The details are in the
published security advisories.
Nineteen of the 21 also affect SMW 5 and 6, and five go back as far as SMW 2.5. Security fixes only go into the latest major version, so if your wiki runs SMW 6 or older, upgrading to SMW 7.3.1 is the way to get them.
Some of the fixes tighten input handling, so requests that previously succeeded may now be rejected, and some HTML that used to render may now show as plain text. If something your wiki depends on stops working after the upgrade, please open an issue.
Also new in 7.3.0
Full-text search no longer ignores short words and stop words that carry a wildcard. A query such as
[[Has text::~to* be]] used to search only for "be" and now also finds words starting with "to", so
such queries can return more results than before.
The new $smwgConfigProfiles setting applies the configuration profiles that ship with SMW, such as
db-primary-keys. See Upgrading if you enabled a profile following the 7.0.0
release notes.
The two releases also fix 12 bugs. Find every change in the release notes of 7.3.0 and 7.3.1.
Use Semantic MediaWiki with AI
You can connect Claude, ChatGPT, and other AI tools to your Semantic MediaWiki via our open source MCP server, and let them run queries or even edit on your behalf. Find out more in Use Semantic MediaWiki with AI.
Credits
These releases were led by our own Alistair Kim, who implemented the bulk of the security enhancements. We thank the security researchers who reported these issues responsibly, and everyone who contributed.
Semantic MediaWiki is free and community-driven. Please consider donating to Semantic MediaWiki to support its continued development.
Upgrading
From 7.3.0, upgrading to 7.3.1 needs no extra steps. From an earlier SMW 7 version, these steps may apply:
-
If your wiki uses properties of type URL, Annotation URI, or Email, run the
rebuildDatamaintenance script, since queries can otherwise miss some values stored by earlier versions. -
If you enabled a configuration profile with the
requireline recommended by the 7.0.0 release notes, that line had no effect. Replace it with$smwgConfigProfilesand runupdate.php, which thedb-primary-keys,elastic-fileingest, andmediaprofiles need. A wiki that loads a profile both ways does not start. -
If you upgrade from a version before 7.2.1 and use Elasticsearch or OpenSearch, run
rebuildElasticIndex --only-updateonce to correct the sort order. -
If you upgrade from a version before 7.2.0 and set
$smwgEntityCollationto auca-*value, runupdateEntityCollation.phponce.
If your wiki runs SMW 6 or older, the upgrade crosses a major version and requires running update.php,
among other steps. SMW 7 also requires MediaWiki 1.43 or later, so wikis on an older MediaWiki need to upgrade that
as well. Our Semantic MediaWiki 7 release post
and the 7.0.0 release notes
describe that upgrade, and the list above applies too. Where those notes recommend a require line for a
configuration profile, use $smwgConfigProfiles instead. Since 7.2.1, the database conversion that
update.php runs for SMW 7 works in batches and resumes where an interrupted run stopped, which helps on
large wikis.
See the upgrading sections of the release notes for the exact commands, and the Semantic MediaWiki 7.3.1 release page for an overview.
Professional Semantic MediaWiki Services
At Professional Wiki, we provide Semantic MediaWiki services, including SMW hosting, SMW software development, SMW consulting, and MediaWiki upgrades. If you would rather not upgrade your wiki yourself, we can do it for you.
Request a wiki with Semantic MediaWiki and it is typically ready within 2 business days.
- Semantic MediaWiki 7.3 Released
- Use Wikidata and Wikibase with AI
- Chameleon 6: Now on Bootstrap 5
- Semantic MediaWiki 7.2.0 Released
- Native Markdown for MediaWiki
- Use Semantic MediaWiki with AI
- Semantic MediaWiki 7 Released
- Introducing NeoWiki and More at MUDCon
- MediaWiki Chatbot Extensions Compared
- Wikibase Faceted Search Released