Project: 
Project machine name: 
leaflet
Date: 
2026-October-07
Vulnerability: 
Cross site scripting
Affected versions: 
<10.4.13
CVE IDs: 
CVE-2026-107265
Description: 

The Leaflet module provides integration with the Leaflet JS mapping library.

Under certain circumstances, when the Leaflet field formatter builds a map it does not filter content titles, leading to a stored cross-site scripting vulnerability.

This vulnerability is mitigated by the fact an attacker needs to have permission to create or edit content that is used in a Leaflet map.

Solution: 

Install the latest version:

  • If you use the Leaflet module, upgrade to release 10.4.13
Coordinated By: