PT-2026-82485 · Element · Maps-Ng

CVE-2026-66155

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Element maps-ng versions prior to 47.12.3 Element maps-ng versions prior to 48.11.3 Element maps-ng versions prior to 49.16.1
Description The si-map component fails to properly neutralize user-controllable input within the points property used to render map pin tooltip labels. This flaw allows an attacker to craft a malicious URL that executes arbitrary script code in the victim's browser session when the victim loads the URL and hovers over a map pin. This is a Cross-Site Scripting (XSS) issue, where malicious scripts are injected into trusted websites.
Recommendations Update Element maps-ng V47 to version 47.12.3 or later. Update Element maps-ng V48 to version 48.11.3 or later. Update Element maps-ng V49 to version 49.16.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66155

Affected Products

Maps-Ng