Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.31%—Weplugins WP Maps1/5/202517/6/2026
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (6.4)0.82%—Mapster WP MapsAI16/11/202417/6/2026
The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaAlta (8.8)0.50%—Mapster WP Maps25/10/202417/6/2026
The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers,…
AplazadaAlta (8.8)0.46%—Weplugins WP MapsAI29/6/202417/6/2026
The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
ModificadaMedia (6.1)1.0%—Wpgmaps WP GO Maps24/1/202417/6/2026
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (5.4)0.33%—Mapster WP Maps8/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology Inc. Mapster WP Maps allows Stored XSS.This issue affects Mapster WP Maps: from n/a through 1.2.38.
ModificadaAlta (8.8)0.30%—Weplugins WP Maps12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
ModificadaMedia (5.4)0.38%—Weplugins WP Maps4/4/202317/6/2026
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
ModificadaAlta (8.8)0.57%—Weplugins WP MapsFedoraproject Fedora11/3/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
ModificadaMedia (4.8)0.67%—Weplugins WP Maps9/8/202117/6/2026
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
ModificadaAlta (7.2)1.4%—Weplugins WP Maps18/3/202117/6/2026
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
ModificadaAlta (8.8)0.70%—Weplugins WP Maps14/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
ModificadaAlta (8.8)0.70%—Weplugins WP Maps14/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
ModificadaAlta (8.8)0.70%—Weplugins WP Maps14/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
ModificadaMedia (6.1)0.98%—Weplugins WP Maps12/8/201917/6/2026
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
ModificadaMedia (6.1)1.0%—Weplugins WP Maps12/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.