Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.38%—Theme Blvd Responsive Google Maps Project Theme Blvd Responsive Google Maps23/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jason Bobich Theme Blvd Responsive Google Maps plugin <= 1.0.2 versions.
ModificadaMedia (4.8)0.38%—Webfactoryltd Maps Widget FOR Google Maps6/4/202317/6/2026
The Maps Widget for Google Maps for WordPress is vulnerable to Stored Cross-Site Scripting via widget settings in versions up to, and including, 4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
ModificadaMedia (5.4)0.38%—Weplugins WP Maps4/4/202317/6/2026
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
ModificadaMedia (5.4)0.39%—Very Simple Google Maps Project Very Simple Google Maps23/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.
ModificadaMedia (6.5)0.75%—Codecabin WP GO Maps14/3/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions.
ModificadaCrítica (9.8)3.9%💥 Exploit10web MAP Builder FOR Google Maps13/3/202317/6/2026
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
ModificadaMedia (5.4)0.48%—Yamaps Project Yamaps13/2/202317/6/2026
The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.52%—Interactive GEO Maps Project Interactive GEO Maps7/2/202317/6/2026
The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor…
ModificadaMedia (5.4)0.56%—Mapsmarker Leaflet Maps Marker6/2/202317/6/2026
The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.4)0.38%—OI Yandex.maps Project OI Yandex.maps23/1/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions.
ModificadaMedia (5.4)0.47%—10web MAP Builder FOR Google Maps23/1/202317/6/2026
The 10WebMapBuilder WordPress plugin before 1.0.72 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaCrítica (9.8)0.67%—Vinylmaps Project Vinylmaps16/1/202317/6/2026
A vulnerability was found in 2071174A vinylmap. It has been classified as critical. Affected is the function contact of the file recordstoreapp/views.py. The manipulation leads to sql injection. The name of the patch is b07b79a1e92cc62574ba0492cce000ef4a7bd25f. It is recommended to apply a patch to fix this issue. The…
ModificadaMedia (5.3)0.73%—Maps-js-icoads Project Maps-js-icoads8/1/202317/6/2026
A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is…
ModificadaMedia (5.3)0.64%—Maps-js-icoads Project Maps-js-icoads8/1/202317/6/2026
A vulnerability was found in saxman maps-js-icoads and classified as critical. This issue affects some unknown processing of the file http-server.js. The manipulation leads to path traversal. The patch is named 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The…
ModificadaAlta (7.2)1.3%—Mapsmarker Leaflet Maps Marker29/8/202217/6/2026
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.
ModificadaAlta (7.5)0.83%—Mapbox Maps Software Development KIT16/8/202217/6/2026
An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes, potentially…
ModificadaMedia (4.8)0.61%—Google Maps Anywhere Project Google Maps Anywhere8/8/202217/6/2026
The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.3)1.3%—Bonn Activity Maps Annotation Tool Project Bonn Activity Maps Annotation Tool11/7/202217/6/2026
The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (6.5)0.53%—Inline Google Maps Project Inline Google Maps20/6/202217/6/2026
The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
ModificadaMedia (4.8)0.59%—Google XML Sitemaps Project Google XML Sitemaps20/6/202217/6/2026
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.3)0.43%—Ayecode API KEY FOR Google Maps15/6/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
ModificadaCrítica (9.8)10%💥 ExploitMapsvg9/5/202217/6/2026
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
ModificadaMedia (6.1)0.80%—Supsystic Easy Google Maps25/4/202217/6/2026
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)1.5%—Bwp-google-xml-sitemaps Project Bwp-google-xml-sitemaps14/3/202217/6/2026
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
ModificadaAlta (8.8)0.57%—Weplugins WP MapsFedoraproject Fedora11/3/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
Orbitaley — Vulnerabilidades