Chargemap operates a web-based electric vehicle charging network and payment platform, with its disclosed vulnerabilities concentrating in authentication and session-management controls around the chargemap.com service. The recurring weakness classes—excessive authentication attempt tolerance, insufficient session expiration, inadequately protected credentials, and missing authentication on critical functions—reflect the access-control demands of a user-facing web application managing payment and network access.
The number and severity of CVEs published that impact products developed by Chargemap over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25851CRITICAL WebSocket endpoints lack proper authentication mechanisms, enabling
attackers to perform unauthorized station impersonation and manipulate
data sent to the backend. An unauthenti | Feb 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-20792CRITICAL The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allow an attacker to conduct denial | Feb 27, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-25711HIGH The WebSocket backend uses charging station identifiers to uniquely
associate sessions but allows multiple endpoints to connect using the
same session identifier. This implementa | Feb 27, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-20791HIGH Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | Feb 27, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chargemap.
Media articles that mention a CVE ID that affects a product developed by Chargemap — matched by CVE ID, not by vendor name.