PatchSiren cyber security CVE debrief
CVE-2026-52854 ProfessionalWiki CVE debrief
A vulnerability in the Maps MediaWiki extension allows for script execution when a user previews or views a map with malicious wikitext. The issue is fixed in version 12.1.3. This vulnerability requires verification of affected versions and remediation. Defenders should prioritize updating to version 12.1.3 to prevent script execution. The vulnerability allows an attacker with edit permission to store malicious wikitext that causes script execution when another user previews or views the affected map.
- Vendor
- ProfessionalWiki
- Product
- Maps
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for MediaWiki installations with the Maps extension should assess exposure and prioritize updating to version 12.1.3. Defenders should care about CVE-2026-52854 because it allows for script execution in user browser sessions, potentially leading to access to user data and actions. The vulnerability requires verification of affected versions and remediation, and defenders should prioritize updating to version 12.1.3.
Why it matters
Defenders should care about CVE-2026-52854 because it allows for script execution in user browser sessions, potentially leading to access to user data and actions. The vulnerability requires verification of affected versions and remediation, and defenders should prioritize updating to version 12.1.3.
- Script execution in user browser sessions
- Access to user data and actions
- Potential for malicious wikitext injection
Technical summary
The Maps MediaWiki extension is vulnerable to script execution due to improper escaping of overlay names in the Leaflet service. An attacker with edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The vulnerability requires verification of affected versions and remediation. Defenders should prioritize updating to version 12.1.3 to prevent script execution. The issue is fixed in version 12.1.3. This vulnerability allows an attacker to execute scripts in user browser sessions, potentially leading to access to user data and actions.
Defensive priority
Defenders should prioritize updating to version 12.1.3 to prevent script execution.
Recommended defensive actions
- Update to version 12.1.3
- Review and update affected MediaWiki installations
- Monitor for malicious wikitext
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to confirm affected versions and remediation. The vulnerability is caused by improper escaping of overlay names in the Leaflet service. The Maps MediaWiki extension is vulnerable to script execution due to this issue. Defenders should verify affected versions and prioritize updating to version 12.1.3.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52854 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52854
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52854 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52854
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ProfessionalWiki/Maps/blob/12.1.3/RELEASE-NOTES.md
-
Source reference
Unverified legacy reference
URL: https://github.com/ProfessionalWiki/Maps/commit/737a993fc2f40499e9bb22198fd1d56c25613806
-
Source reference
Unverified legacy reference
URL: https://github.com/ProfessionalWiki/Maps/pull/899
-
Source reference
Unverified legacy reference
URL: https://github.com/ProfessionalWiki/Maps/releases/tag/12.1.3
-
Source reference
Unverified legacy reference
URL: https://github.com/ProfessionalWiki/Maps/security/advisories/GHSA-4h7g-5542-v3fc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.