« Volver al listado

Supsystic

Supsystic Easy Google Maps: vulnerabilidades y CVE

Supsystic Easy Google Maps tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses3
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-102395Alta (7.1)0.25%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
CVE-2026-73367Alta (7.2)0.33%—18 ago 2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
CVE-2026-73366Crítica (9.8)0.56%—18 ago 2026
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVE-2025-32138Media (6.6)0.52%—4 abr 2025
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18.
CVE-2024-5219Media (5.4)0.34%—2 jul 2024
The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output…
CVE-2024-31269Alta (8.8)0.23%—12 abr 2024
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11.
CVE-2023-2526Media (5.4)0.28%—9 jun 2023
The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes…
CVE-2023-33926Alta (8.8)0.25%—28 may 2023
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions.
CVE-2021-46780Media (6.1)0.80%—25 abr 2022
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
CVE-2021-39346Media (4.8)0.97%—1 nov 2021
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript1
  2. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Supsystic