CVE-2022-29904
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain ‘-‘ and ‘_’ constraints.
Date published : 2022-04-28
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/SemanticDrilldown/+/785213