← Back to CVE search

CVE-2026-52854

Maps

Description

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user-s browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3.

CVSS 8.6EPSS 0.43299999999999994%Risk 0.89
View source
Published
2026-08-18 22:16:53
Affected versions
<12.1.3
Type
Library
Last modified
2026-08-19 19:17:18
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L