Mapos develops a map operating system product with a narrowly focused vulnerability footprint that is more prominent in its threat landscape than its modest disclosure volume would suggest. The recurring exposure centers on cross-site scripting weaknesses in web-facing interfaces, a class of input-handling flaw common to mapping and geospatial platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mapos over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48327MEDIUM Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) dataInicial, (2) dataFinal, (3) | Feb 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2022-48326MEDIUM Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) nome, (2) aCliente, (3) eClient | Feb 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2022-48324MEDIUM Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) pesquisa, (2) data, (3) data2, | Feb 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2017-16919MEDIUM MapOS 3.1.11 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in /clientes/visualizar, which allows remote attackers to inject arbitrary web script or HTML via a c | Nov 21, 2017 | 5.4 | 20 | NO | NO |
CVE-2022-48325MEDIUM Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSen | Feb 16, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-35545MEDIUM MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability. | Jun 26, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-36819MEDIUM MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a | Jun 25, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mapos.
Media articles that mention a CVE ID that affects a product developed by Mapos — matched by CVE ID, not by vendor name.