mapsplugin records
7 published records for vendor mapsplugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-91 XML Injection (aka Blind XPath Injection)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2013-7429No exploit | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemapsplugin · googlemaps · CWE-91 | Critical9.8 | — | 2.2% | Sep 14, 2017 |
31Monitor | CVE-2013-7428No exploit | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2mapsplugin · googlemaps · CWE-400 | High7.5 | — | 1.9% | Sep 7, 2017 |
30Monitor | CVE-2013-7432No exploit | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.mapsplugin · googlemaps · CWE-264 | High7.5 | — | 1.6% | Aug 29, 2017 |
24Monitor | CVE-2013-7433No exploit | Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.mapsplugin · googlemaps · CWE-79 | Medium6.1 | — | 0.9% | Aug 29, 2017 |
24Monitor | CVE-2013-7430No exploit | Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web scrmapsplugin · googlemaps · CWE-79 | Medium6.1 | — | 0.8% | Aug 28, 2017 |
23Monitor | CVE-2014-9686No exploit | The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to causemapsplugin · googlemaps · CWE-399 | Medium5.9 | — | 1.6% | Sep 27, 2017 |
21Monitor | CVE-2013-7431No exploit | Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.mapsplugin · googlemaps · CWE-200 | Medium5.3 | — | 1.1% | Aug 29, 2017 |
- CVE-2013-742940Plan
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_google
CriticalCVSS 9.8No exploitEPSS 2%mapsplugin · googlemapsSep 14, 2017
- CVE-2013-742831Monitor
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2
HighCVSS 7.5No exploitEPSS 2%mapsplugin · googlemapsSep 7, 2017
- CVE-2013-743230Monitor
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
HighCVSS 7.5No exploitEPSS 2%mapsplugin · googlemapsAug 29, 2017
- CVE-2013-743324Monitor
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.
MediumCVSS 6.1No exploitEPSS 1%mapsplugin · googlemapsAug 29, 2017
- CVE-2013-743024Monitor
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web scr
MediumCVSS 6.1No exploitEPSS 1%mapsplugin · googlemapsAug 28, 2017
- CVE-2014-968623Monitor
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause
MediumCVSS 5.9No exploitEPSS 2%mapsplugin · googlemapsSep 27, 2017
- CVE-2013-743121Monitor
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
MediumCVSS 5.3No exploitEPSS 1%mapsplugin · googlemapsAug 29, 2017