Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Thinkupthemes Responsive Vector Maps | 7/2/2022 | 17/6/2026 | The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server | |
| Modificada | Alta (8.8) | 0.52% | — | Xml-sitemaps Unlimited Sitemap Generator | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page. | |
| Modificada | Media (4.8) | 0.97% | — | Supsystic Easy Google Maps | 1/11/2021 | 17/6/2026 | The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.90% | — | Amazingweb Wp-design-maps-places | 10/9/2021 | 17/6/2026 | The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2. | |
| Modificada | Media (5.4) | 0.56% | — | Codecabin WP GO Maps | 9/9/2021 | 17/6/2026 | Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title. | |
| Modificada | Media (5.4) | 0.58% | — | Codecabin WP GO Maps | 9/9/2021 | 17/6/2026 | Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address. | |
| Modificada | Media (6.1) | 0.90% | — | Scribblemaps Scribble Maps | 16/8/2021 | 17/6/2026 | The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includes/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2. | |
| Modificada | Media (4.8) | 0.67% | — | Weplugins WP Maps | 9/8/2021 | 17/6/2026 | The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 2.5% | 💥 Exploit | Codecabin WP GO Maps | 21/6/2021 | 17/6/2026 | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (5.3) | 1.5% | — | Osgeo MapserverFedoraproject Fedora | 6/5/2021 | 17/6/2026 | MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI). | |
| Modificada | Media (6.1) | 18% | 💥 Exploit | Supsystic Ultimate Maps | 5/5/2021 | 17/6/2026 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.2) | 1.4% | — | Weplugins WP Maps | 18/3/2021 | 17/6/2026 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+). | |
| Modificada | Alta (7.6) | 1.6% | — | Osm-static-maps Project Osm-static-maps | 20/10/2020 | 17/6/2026 | This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives… | |
| Modificada | Media (6.1) | 5.7% | 💥 Exploit | Heroplugins Hero Maps Premium | 26/2/2020 | 17/6/2026 | The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user… | |
| Modificada | Media (6.1) | 1.0% | — | Infoware Mapsuite | 31/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Devfarm WP GPX Maps | 23/1/2020 | 16/6/2026 | WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | |
| Modificada | Media (6.1) | 1.1% | — | Formget Contact Form Integrated With Google Maps | 23/1/2020 | 17/6/2026 | The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS | |
| Modificada | Alta (8.1) | 2.4% | — | Gatewaygeomatics Mapserver | 9/1/2020 | 16/6/2026 | Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Osgeo Mapserver | 29/10/2019 | 16/6/2026 | Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing. | |
| Modificada | Alta (7.5) | 1.4% | — | Mapsolutions Intramaps | 5/9/2019 | 17/6/2026 | A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Bestwebsoft Google Maps | 21/8/2019 | 17/6/2026 | The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues. | |
| Modificada | Alta (8.8) | 0.70% | — | Weplugins WP Maps | 14/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. | |
| Modificada | Alta (8.8) | 0.70% | — | Weplugins WP Maps | 14/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. | |
| Modificada | Alta (8.8) | 0.70% | — | Weplugins WP Maps | 14/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. | |
| Modificada | Media (6.1) | 0.98% | — | Weplugins WP Maps | 12/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. |