Imagemapper Project maintains a web-based image mapping utility with a narrowly focused product scope, where disclosed vulnerabilities center on web-application input handling and access control—specifically cross-site request forgery, cross-site scripting, and missing authorization checks. These weakness classes are typical of interactive web tools that process and render user-supplied content without sufficient validation or protection boundaries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imagemapper Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5532MEDIUM The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on th | Nov 7, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-5507MEDIUM The ImageMapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'imagemap' shortcode in versions up to, and including, 1.2.6 due to insufficient input sanitiz | Nov 7, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-5975MEDIUM The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on mu | Nov 7, 2023 | 4.3 | 15 | NO | NO |
CVE-2023-5506MEDIUM The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and i | Nov 7, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imagemapper Project.
Media articles that mention a CVE ID that affects a product developed by Imagemapper Project — matched by CVE ID, not by vendor name.