Mayan-edms
Mayan-edms Mayan Edms: vulnerabilidades y CVE
Mayan-edms Mayan Edms tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-14692 | Baja (2.1) | 0.46% | — | 15 dic 2025 | A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes open redirect. It is possible to initiate the attack remotely. The… |
| CVE-2025-14691 | Baja (2.1) | 0.46% | — | 14 dic 2025 | A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from… |
| CVE-2022-47419 | Media (5.4) | 0.54% | — | 7 feb 2023 | An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system. |
| CVE-2018-16407 | Media (6.1) | 1.2% | — | 3 sept 2018 | An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. |
| CVE-2018-16406 | Media (6.1) | 1.3% | — | 3 sept 2018 | An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. |
| CVE-2018-16405 | Media (6.1) | 1.4% | — | 3 sept 2018 | An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. |
| CVE-2014-3840 | Baja (3.5) | 3.5% | — | 27 may 2014 | Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2)… |