Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 20 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leafletjs
Leafletjs leaflet |
|
| CPEs | cpe:2.3:a:leafletjs:leaflet:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Leafletjs
Leafletjs leaflet |
Wed, 15 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leaflet
Leaflet leaflet |
|
| Vendors & Products |
Leaflet
Leaflet leaflet |
Wed, 15 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting via Unfiltered Popup Content in Leaflet ≤1.9.4 | Leaflet: Leaflet: Cross-Site Scripting (XSS) via unsanitized input in bindPopup() method |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 14 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting via Unfiltered Popup Content in Leaflet ≤1.9.4 | |
| Weaknesses | CWE-79 |
Tue, 14 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-21T17:36:25.753Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69993
Updated: 2026-04-14T17:45:21.468Z
Status : Modified
Published: 2026-04-14T15:16:25.477
Modified: 2026-04-21T18:16:19.760
Link: CVE-2025-69993
OpenCVE Enrichment
Updated: 2026-04-15T21:03:03Z