Magicpin operates a location-based mobile commerce and discovery application, with its vulnerability footprint concentrated in web-facing and application-layer components. The observed weakness classes center on input-handling and XML processing, specifically cross-site scripting and improper XML external entity reference handling, reflecting the data-handling demands of web and mobile services.
The number and severity of CVEs published that impact products developed by Magicpin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31447HIGH An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file. | Jun 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-28927MEDIUM There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker c | Nov 23, 2020 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magicpin.
Media articles that mention a CVE ID that affects a product developed by Magicpin — matched by CVE ID, not by vendor name.