Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)3.1%💥 ExploitThinkupthemes Responsive Vector Maps7/2/202217/6/2026
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server
ModificadaAlta (8.8)0.52%—Xml-sitemaps Unlimited Sitemap Generator24/11/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page.
ModificadaMedia (4.8)0.97%—Supsystic Easy Google Maps1/11/202117/6/2026
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web…
ModificadaMedia (6.1)0.90%—Amazingweb Wp-design-maps-places10/9/202117/6/2026
The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.
ModificadaMedia (5.4)0.56%—Codecabin WP GO Maps9/9/202117/6/2026
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.
ModificadaMedia (5.4)0.58%—Codecabin WP GO Maps9/9/202117/6/2026
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
ModificadaMedia (6.1)0.90%—Scribblemaps Scribble Maps16/8/202117/6/2026
The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includes/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.
ModificadaMedia (4.8)0.67%—Weplugins WP Maps9/8/202117/6/2026
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)2.5%💥 ExploitCodecabin WP GO Maps21/6/202117/6/2026
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaMedia (5.3)1.5%—Osgeo MapserverFedoraproject Fedora6/5/202117/6/2026
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
ModificadaMedia (6.1)18%💥 ExploitSupsystic Ultimate Maps5/5/202117/6/2026
The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
ModificadaAlta (7.2)1.4%—Weplugins WP Maps18/3/202117/6/2026
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
ModificadaAlta (7.6)1.6%—Osm-static-maps Project Osm-static-maps20/10/202017/6/2026
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives…
ModificadaMedia (6.1)5.7%💥 ExploitHeroplugins Hero Maps Premium26/2/202017/6/2026
The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user…
ModificadaMedia (6.1)1.0%—Infoware Mapsuite31/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)16%💥 ExploitDevfarm WP GPX Maps23/1/202016/6/2026
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
ModificadaMedia (6.1)1.1%—Formget Contact Form Integrated With Google Maps23/1/202017/6/2026
The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
ModificadaAlta (8.1)2.4%—Gatewaygeomatics Mapserver9/1/202016/6/2026
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.
ModificadaAlta (7.5)2.2%—Osgeo Mapserver29/10/201916/6/2026
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
ModificadaAlta (7.5)1.4%—Mapsolutions Intramaps5/9/201917/6/2026
A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Google Maps21/8/201917/6/2026
The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
ModificadaAlta (8.8)0.70%—Weplugins WP Maps14/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
ModificadaAlta (8.8)0.70%—Weplugins WP Maps14/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
ModificadaAlta (8.8)0.70%—Weplugins WP Maps14/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
ModificadaMedia (6.1)0.98%—Weplugins WP Maps12/8/201917/6/2026
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.