Cross-Site Scripting in MediaWiki Maps Extension by ProfessionalWiki
CVE-2026-52854
8.6HIGH
What is CVE-2026-52854?
The Maps extension for MediaWiki allows geographic data visualization using dynamic maps. A vulnerability exists in the display_map parser function prior to version 12.1.3. This issue permits the insertion of attacker-controlled HTML in the overlays parameter. As a result, a user with edit permissions can embed malicious scripts within the wikitext, which execute when another user previews or views the affected map. This execution occurs in the context of the viewer's browser session, allowing unauthorized access to their data and potentially harmful actions. The issue has been rectified in version 12.1.3, which users are strongly encouraged to upgrade to in order to mitigate the risks.
Affected Version(s)
Maps < 12.1.3
