Icopydoc maintains a narrow set of e-commerce and content-distribution plugins, including product-feed modules for Yandex Market and Google Merchant Center as well as mapping integrations for WordPress. The vendor's recurring exposure centers on cross-site scripting vulnerabilities across these web-facing plugins, reflecting the input-handling complexity inherent to content-generation and data-rendering layers. Live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icopydoc over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30473MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 versions. | Aug 16, 2023 | 6.1 | 22 | NO | NO |
CVE-2025-57952MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Maps for WP maps-for-wp allows Stored XSS.This issue affects Maps for | Sep 22, 2025 | 5.9 | 20 | NO | NO |
CVE-2025-32179MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Maps for WP maps-for-wp allows Stored XSS.This issue affects Maps for | Apr 4, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-9378MEDIUM The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.7.2 due to insuffici | Oct 2, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-1365MEDIUM The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the feed_id parameter in all versions up to, and including, 4.2.3 due to insuffi | Mar 13, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-13406MEDIUM The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due | Jan 22, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-30877MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 versions. | Aug 17, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-13648MEDIUM The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortcode in all versions up to, and including, 1.2.4 due to insuff | Feb 21, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icopydoc.
Media articles that mention a CVE ID that affects a product developed by Icopydoc — matched by CVE ID, not by vendor name.