PT-2026-55481 · Professionalwiki+3 · Maps+2

CVE-2026-52854

·

Published

2026-07-02

·

Updated

2026-08-20

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Maps versions prior to 12.1.3
Description The display map parser function in the Leaflet service fails to properly escape the overlays parameter. This occurs because resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without sanitization. A user with edit permissions can store malicious wikitext that triggers script execution in the browser session of any user who previews or views the affected map, potentially allowing access to data or unauthorized actions.
Recommendations Update to version 12.1.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52854
GHSA-4H7G-5542-V3FC

Affected Products

Maps
Mediawiki
Mediawiki/Maps