Cross-Site Scripting in MediaWiki Maps Extension by ProfessionalWiki
CVE-2026-52854

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-52854?

The Maps extension for MediaWiki allows geographic data visualization using dynamic maps. A vulnerability exists in the display_map parser function prior to version 12.1.3. This issue permits the insertion of attacker-controlled HTML in the overlays parameter. As a result, a user with edit permissions can embed malicious scripts within the wikitext, which execute when another user previews or views the affected map. This execution occurs in the context of the viewer's browser session, allowing unauthorized access to their data and potentially harmful actions. The issue has been rectified in version 12.1.3, which users are strongly encouraged to upgrade to in order to mitigate the risks.

Affected Version(s)

Maps < 12.1.3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.