Mapfish is a specialized geospatial web mapping and printing toolkit with a focused product portfolio centered on its print module, used for server-side generation of map-based documents. Its disclosed vulnerabilities cluster around web-layer input handling, specifically cross-site scripting and XML external entity injection, which are characteristic of applications that process and render user-supplied geographic or document data.
The number and severity of CVEs published that impact products developed by Mapfish over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15232CRITICAL In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style. | Oct 2, 2020 | 9.1 | 28 | NO | NO |
CVE-2020-15231MEDIUM In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting. | Oct 2, 2020 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mapfish.
Media articles that mention a CVE ID that affects a product developed by Mapfish — matched by CVE ID, not by vendor name.