CVE Feed

    Dashboard / CVE / CVE-2025-69993

    CVE-2025-69993

    Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

    Published:Apr 14, 2026
    Last Modified:Apr 21, 2026
    EPS:Apr 14, 2026
    EPSS Score:0.0003
    CVSS Score:6.1

    Affected Products

    Vendor
    Leaflet
    Product
    Leaflet
    Vendor
    Leafletjs
    Product
    Leaflet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High