Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.31% | — | Weplugins WP Maps | 1/5/2025 | 17/6/2026 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.82% | — | Mapster WP MapsAI | 16/11/2024 | 17/6/2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Alta (8.8) | 0.50% | — | Mapster WP Maps | 25/10/2024 | 17/6/2026 | The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.8) | 0.46% | — | Weplugins WP MapsAI | 29/6/2024 | 17/6/2026 | The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Media (6.1) | 1.0% | — | Wpgmaps WP GO Maps | 24/1/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (5.4) | 0.33% | — | Mapster WP Maps | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology Inc. Mapster WP Maps allows Stored XSS.This issue affects Mapster WP Maps: from n/a through 1.2.38. | |
| Modificada | Alta (8.8) | 0.30% | — | Weplugins WP Maps | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Weplugins WP Maps | 4/4/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions. | |
| Modificada | Alta (8.8) | 0.57% | — | Weplugins WP MapsFedoraproject Fedora | 11/3/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). | |
| Modificada | Media (4.8) | 0.67% | — | Weplugins WP Maps | 9/8/2021 | 17/6/2026 | The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.2) | 1.4% | — | Weplugins WP Maps | 18/3/2021 | 17/6/2026 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+). | |
| Modificada | Alta (8.8) | 0.70% | — | Weplugins WP Maps | 14/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. | |
| Modificada | Alta (8.8) | 0.70% | — | Weplugins WP Maps | 14/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. | |
| Modificada | Alta (8.8) | 0.70% | — | Weplugins WP Maps | 14/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. | |
| Modificada | Media (6.1) | 0.98% | — | Weplugins WP Maps | 12/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.0% | — | Weplugins WP Maps | 12/8/2019 | 17/6/2026 | The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. |