High severityNVD Advisory· Published Jul 2, 2026
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
CVE-2026-52854
Description
Summary
Stored XSS through wikitext can be performed by inserting malicious HTML into the overlays parameter of the display_map parser function when using the leaflet service.
Details
The maps extension doesn't escape overlay names before passing them to leaflet. Leaflet then inserts them as HTML: https://github.com/ProfessionalWiki/Maps/blob/ca5139fabd75f3c34f47ea3fd161306506b053bc/resources/lib/leaflet/leaflet.js#L5243
PoC
Preview the following wikitext, using the default configuration options of the extension: `` {{#display_map:0,0|service=leaflet|overlays=OpenTopoMap.}} ``
Impact
Stored XSS can be performed by any user with the edit permission.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mediawiki/mapsPackagist | < 12.1.3 | 12.1.3 |
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.