VYPR
High severityNVD Advisory· Published Jul 2, 2026

mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function

CVE-2026-52854

Description

Summary

Stored XSS through wikitext can be performed by inserting malicious HTML into the overlays parameter of the display_map parser function when using the leaflet service.

Details

The maps extension doesn't escape overlay names before passing them to leaflet. Leaflet then inserts them as HTML: https://github.com/ProfessionalWiki/Maps/blob/ca5139fabd75f3c34f47ea3fd161306506b053bc/resources/lib/leaflet/leaflet.js#L5243

PoC

Preview the following wikitext, using the default configuration options of the extension: `` {{#display_map:0,0|service=leaflet|overlays=OpenTopoMap.}} ``

Impact

Stored XSS can be performed by any user with the edit permission.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mediawiki/mapsPackagist
< 12.1.312.1.3

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.