PT-2026-55481 · Professionalwiki+3 · Maps+2
CVE-2026-52854
·
Published
2026-07-02
·
Updated
2026-08-20
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Maps versions prior to 12.1.3
Description
The
display map parser function in the Leaflet service fails to properly escape the overlays parameter. This occurs because resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without sanitization. A user with edit permissions can store malicious wikitext that triggers script execution in the browser session of any user who previews or views the affected map, potentially allowing access to data or unauthorized actions.Recommendations
Update to version 12.1.3.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maps
Mediawiki
Mediawiki/Maps