VYPR

Maps

by MediaWiki

CVEs (1)

  • CVE-2026-52854higJul 2, 2026
    risk 0.45cvss epss

    ### Summary Stored XSS through wikitext can be performed by inserting malicious HTML into the `overlays` parameter of the `display_map` parser function when using the leaflet service. ### Details The maps extension doesn't escape overlay names before passing them to leaflet.…