« Volver al listado

Cyberhobo

Cyberhobo GEO Mashup: vulnerabilidades y CVE

Cyberhobo GEO Mashup tiene 18 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE18
Últimos 12 meses13
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97250Alta (7.1)0.15%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-78294Media (6.5)0.22%—17 sept 2026
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-66450Alta (8.1)0.47%—13 ago 2026
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
CVE-2026-66449Alta (7.1)0.25%—13 ago 2026
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
CVE-2026-48967Alta (8.5)0.36%—17 jun 2026
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
CVE-2026-7552Media (5.3)0.58%—28 may 2026
The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action.…
CVE-2026-42734Alta (7.1)0.25%—27 may 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Reflected XSS.This issue affects Geo Mashup: from n/a through <= 1.13.19.
CVE-2026-27427Media (6.5)0.22%—26 may 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.
CVE-2026-4062Alta (7.5)0.51%—2 may 2026
The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to insufficient escaping…
CVE-2026-4061Alta (7.5)0.51%—2 may 2026
The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook explicitly calling…
CVE-2026-4060Alta (7.5)1.6%—2 may 2026
The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameter…
CVE-2026-6457Media (6.5)0.47%—2 may 2026
The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to insufficient escaping on the user…
CVE-2026-2416Alta (7.5)1.4%—25 feb 2026
The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of…
CVE-2025-48293Crítica (9.8)0.43%—14 ago 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows PHP Local File Inclusion.This issue affects Geo Mashup:…
CVE-2024-8990Media (6.4)0.39%—1 oct 2024
The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 due to insufficient input…
CVE-2024-44008Media (5.4)0.31%—17 sept 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Stored XSS.This issue affects Geo Mashup: from n/a through <= 1.13.12.
CVE-2018-14071Crítica (9.8)3.1%—16 jul 2018
The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.
CVE-2015-1383Media (4.3)2.0%—2 feb 2015
Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search key.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System6
  2. T1190 Exploit Public-Facing Application6
  3. T1059.007 JavaScript3
  4. T1189 Drive-by Compromise3
  5. T1059 Command and Scripting Interpreter1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.