Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Easy Google MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | |
| Aplazada | Alta (7.2) | 0.33% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | WP Google Maps PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | |
| Aplazada | Media (6.1) | 0.37% | — | WP Google Maps IntegrationAI | 12/5/2026 | 17/6/2026 | The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.35% | — | Basic Google Maps PlacemarksAI | 16/4/2026 | 17/6/2026 | The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify stored map latitude and… | |
| Aplazada | Media (6.4) | 0.22% | — | Coon Google MapsAI | 11/11/2025 | 17/6/2026 | The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'map' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | Flippercode Advanced Google MapsAI | 6/11/2025 | 30/9/2026 | Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Google Maps: from n/a through <= 5.8.4. | |
| Aplazada | Media (5.4) | 0.24% | — | Pronamic Google MapsAI | 28/8/2025 | 17/6/2026 | The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.29% | — | Bernd Altmeier Google Maps GPX ViewerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bernd Altmeier Google Maps GPX Viewer google-maps-gpx-viewer allows Reflected XSS.This issue affects Google Maps GPX Viewer: from n/a through <= 3.6. | |
| Analizada | Media (5.9) | 0.32% | — | Google Maps\ Store Locator Project | 16/4/2025 | 17/6/2026 | Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*. | |
| Aplazada | Media (6.6) | 0.52% | — | Supsystic Easy Google MapsAI | 4/4/2025 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18. | |
| Aplazada | Media (6.5) | 0.27% | — | Aaron D. Campbell Google-maps-for-wordpressAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress google-maps-for-wordpress allows DOM-Based XSS.This issue affects Google Maps for WordPress: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.5) | 0.23% | — | Fengler Magic Google MapsAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fengler Magic Google Maps magic-google-maps allows Stored XSS.This issue affects Magic Google Maps: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.20% | — | BAS Matthee LSD Google Maps EmbedderAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bas Matthee LSD Google Maps Embedder lsd-google-maps-embedder allows Cross Site Request Forgery.This issue affects LSD Google Maps Embedder: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Agilelogix Free Google MapsAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agile Logix Free Google Maps wp-map allows Stored XSS.This issue affects Free Google Maps: from n/a through <= 1.0.1. | |
| Modificada | Media (4.3) | 0.29% | — | 10web MAP Builder FOR Google Maps | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.73. | |
| Aplazada | Media (6.5) | 0.28% | — | Pronamic Google MapsAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pronamic Pronamic Google Maps pronamic-google-maps allows Stored XSS.This issue affects Pronamic Google Maps: from n/a through <= 2.3.2. | |
| Aplazada | Media (6.5) | 0.32% | — | Imbaa Responsive Google MapsAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov Responsive Google Maps | by imbaa responsive-google-maps allows Stored XSS.This issue affects Responsive Google Maps | by imbaa: from n/a through <= 1.2.5. | |
| Aplazada | Media (6.4) | 0.34% | — | Simple Shortcode FOR Google MapsAI | 8/11/2024 | 17/6/2026 | The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.34% | — | Supsystic Easy Google Maps | 2/7/2024 | 17/6/2026 | The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,… | |
| Modificada | Alta (8.8) | 0.23% | — | Supsystic Easy Google Maps | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11. | |
| Modificada | Alta (7.2) | 0.54% | — | 10web MAP Builder FOR Google Maps | 31/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.74. | |
| Modificada | Alta (8.8) | 0.50% | — | Codepeople Google Maps CP | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Google Maps CP.This issue affects Google Maps CP: from n/a through 1.0.43. | |
| Modificada | Media (5.4) | 0.53% | — | Qoders Upqode Google Maps | 16/1/2024 | 17/6/2026 | The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |