Mapgis develops geospatial information system software, with its IGServer product serving as a core component for spatial data management and analysis across enterprise deployments. The vendor's vulnerability profile centers on a durable authentication weakness: the use of hard-coded credentials in IGServer, which represents a structural risk in products where credential management is embedded rather than externalized.
The number and severity of CVEs published that impact products developed by Mapgis over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36170HIGH MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion. | Aug 19, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-36171HIGH MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion. | Aug 19, 2022 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mapgis.
Media articles that mention a CVE ID that affects a product developed by Mapgis — matched by CVE ID, not by vendor name.