Cyberhobo's vulnerability footprint centers on the Geo Mashup plugin, a geolocation and mapping extension characterized by application-layer input-handling weaknesses. The recurring signal reflects cross-site scripting and improper input validation issues typical of web-facing data-display components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cyberhobo over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2416HIGH The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on t | Feb 25, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-4062HIGH The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18 | May 2, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-4061HIGH The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `S | May 2, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-4060HIGH The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient es | May 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-6457MEDIUM The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to | May 2, 2026 | 6.5 | 27 | NO | NO |
CVE-2018-14071CRITICAL The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input. | Jul 16, 2018 | 9.8 | 26 | NO | NO |
CVE-2026-7552MEDIUM The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a use | May 28, 2026 | 5.3 | 21 | NO | NO |
CVE-2024-8990MEDIUM The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13 | Oct 1, 2024 | 6.4 | 19 | NO | NO |
CVE-2024-44008MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Stored XSS.This issue affects Geo Ma | Sep 17, 2024 | 5.4 | 16 | NO | NO |
CVE-2015-1383MEDIUM Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML | Feb 2, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cyberhobo.
Media articles that mention a CVE ID that affects a product developed by Cyberhobo — matched by CVE ID, not by vendor name.