codecabin records
18 published records for vendor codecabin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.6%
- Pre-auth RCE
- 0
- With a fix record
- 22.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2019-10692Weaponized | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before codecabin · wp go maps · CWE-89 | Critical9.8 | — | 78.7% | Apr 2, 2019 |
35Monitor | CVE-2025-24742No exploit | WordPress WP Google Maps plugin <= 9.0.40 - Cross Site Request Forgery (CSRF) vulnerabilitycodecabin · wp go maps · CWE-352 | High8.8 | — | 0.2% | Jan 27, 2025 |
26Monitor | CVE-2023-6777No exploit | WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Servicecodecabin · wp go maps · CWE-200 | Medium6.5 | — | 0.8% | Apr 9, 2024 |
26Monitor | CVE-2022-47595No exploit | WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversalcodecabin · wp go maps · CWE-22 | Medium6.5 | — | 0.8% | Mar 14, 2023 |
25Monitor | CVE-2019-9912Proof of concept | The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.codecabin · wp go maps · CWE-79 | Medium6.1 | — | 3.2% | Mar 21, 2019 |
24Monitor | CVE-2024-29931Proof of concept | WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerabilitycodecabin · wp go maps · CWE-79 | Medium6.1 | — | 0.8% | Mar 27, 2024 |
24Monitor | CVE-2024-13628Proof of concept | WP Pricing Table <= 1.1 - Reflected XSScodecabin · wp pricing table · CWE-79 | Medium6.1 | — | 0.7% | Feb 26, 2025 |
24Monitor | CVE-2023-6627No exploit | WP Go Maps < 9.0.28 - Unauthenticated Stored XSScodecabin · wp go maps · CWE-79 | Medium6.1 | — | 0.6% | Jan 8, 2024 |
22Monitor | CVE-2021-24383Proof of concept | WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)codecabin · wp go maps · CWE-79 | Medium5.4 | — | 2.5% | Jun 21, 2021 |
21Monitor | CVE-2019-14792No exploit | The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.codecabin · wp go maps · CWE-79 | Medium5.4 | — | 1.1% | Aug 9, 2019 |
21Monitor | CVE-2021-36870No exploit | WordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilitiescodecabin · wp go maps · CWE-79 | Medium5.4 | — | 0.6% | Sep 9, 2021 |
21Monitor | CVE-2021-36871No exploit | WordPress WP Google Maps Pro premium plugin <= 8.1.11 - Multiple Authenticated Persistent XSS vulnerabilitiescodecabin · wp go maps · CWE-79 | Medium5.4 | — | 0.6% | Sep 9, 2021 |
21Monitor | CVE-2024-5994No exploit | WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scriptingcodecabin · wp go maps · CWE-79 | Medium5.4 | — | 0.4% | Jun 14, 2024 |
21Monitor | CVE-2024-9127No exploit | Super Testimonials <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via alignment Parametercodecabin · super testimonials · CWE-79 | Medium5.4 | — | 0.3% | Sep 26, 2024 |
21Monitor | CVE-2024-3557No exploit | WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodecodecabin · wp go maps · CWE-79 | Medium5.4 | — | 0.3% | May 24, 2024 |
21Monitor | CVE-2024-1582No exploit | WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodecodecabin · wp go maps · CWE-79 | Medium5.4 | — | 0.3% | Mar 12, 2024 |
19Monitor | CVE-2023-4839No exploit | WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scriptingcodecabin · wp go maps · CWE-79 | Medium4.8 | — | 0.3% | Mar 12, 2024 |
18Monitor | CVE-2014-7182No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to injeccodecabin · wp go maps · CWE-79 | Medium4.3 | — | 2.5% | Oct 22, 2014 |
- CVE-2019-1069263This week
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before
CriticalCVSS 9.8WeaponizedEPSS 79%codecabin · wp go mapsApr 2, 2019
- CVE-2025-2474235Monitor
WordPress WP Google Maps plugin <= 9.0.40 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%codecabin · wp go mapsJan 27, 2025
- CVE-2023-677726Monitor
WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service
MediumCVSS 6.5No exploitEPSS 1%codecabin · wp go mapsApr 9, 2024
- CVE-2022-4759526Monitor
WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal
MediumCVSS 6.5No exploitEPSS 1%codecabin · wp go mapsMar 14, 2023
- CVE-2019-991225Monitor
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
MediumCVSS 6.1Proof of conceptEPSS 3%codecabin · wp go mapsMar 21, 2019
- CVE-2024-2993124Monitor
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1Proof of conceptEPSS 1%codecabin · wp go mapsMar 27, 2024
- CVE-2024-1362824Monitor
WP Pricing Table <= 1.1 - Reflected XSS
MediumCVSS 6.1Proof of conceptEPSS 1%codecabin · wp pricing tableFeb 26, 2025
- CVE-2023-662724Monitor
WP Go Maps < 9.0.28 - Unauthenticated Stored XSS
MediumCVSS 6.1No exploitEPSS 1%codecabin · wp go mapsJan 8, 2024
- CVE-2021-2438322Monitor
WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)
MediumCVSS 5.4Proof of conceptEPSS 2%codecabin · wp go mapsJun 21, 2021
- CVE-2019-1479221Monitor
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
MediumCVSS 5.4No exploitEPSS 1%codecabin · wp go mapsAug 9, 2019
- CVE-2021-3687021Monitor
WordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%codecabin · wp go mapsSep 9, 2021
- CVE-2021-3687121Monitor
WordPress WP Google Maps Pro premium plugin <= 8.1.11 - Multiple Authenticated Persistent XSS vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%codecabin · wp go mapsSep 9, 2021
- CVE-2024-599421Monitor
WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%codecabin · wp go mapsJun 14, 2024
- CVE-2024-912721Monitor
Super Testimonials <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via alignment Parameter
MediumCVSS 5.4No exploitEPSS 0%codecabin · super testimonialsSep 26, 2024
- CVE-2024-355721Monitor
WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%codecabin · wp go mapsMay 24, 2024
- CVE-2024-158221Monitor
WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%codecabin · wp go mapsMar 12, 2024
- CVE-2023-483919Monitor
WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%codecabin · wp go mapsMar 12, 2024
- CVE-2014-718218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to injec
MediumCVSS 4.3No exploitEPSS 2%codecabin · wp go mapsOct 22, 2014