The Leaflet module provides integration with the Leaflet JS mapping library.
Under certain circumstances, when the Leaflet field formatter builds a map it does not filter content titles, leading to a stored cross-site scripting vulnerability.
This vulnerability is mitigated by the fact an attacker needs to have permission to create or edit content that is used in a Leaflet map.