Known Vulnerabilities for Leaflet by Leafletjs
Listed below are 1 of the newest known vulnerabilities associated with "Leaflet" by "Leafletjs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-39646 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map leaf... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2026-5451 json | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' sh... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-4389 json | The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... | Not Provided | 2026-03-26 | 2026-03-26 |
| CVE-2025-69993 json | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This meth... | Not Provided | 2026-04-14 | 2026-04-21 |
| CVE-2025-27278 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Ghedini AcuGIS Le... | Not Provided | 2025-03-03 | 2026-04-23 |
| CVE-2024-3670 json | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scrip... | Not Provided | 2024-05-02 | 2026-04-08 |
| CVE-2023-5050 json | The Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and inclu... | Not Provided | 2023-10-20 | 2026-04-08 |