Mapsmarker is a web-mapping plugin and tool suite centered on its Leaflet Maps Marker product, where the durable signal is concentrated in web application layer input handling. The recurring weakness classes—cross-site scripting and SQL injection—reflect the product's direct exposure to untrusted user input in mapping queries and marker configuration, which are characteristic risks in web-facing geolocation tools. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mapsmarker over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2913MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to | May 21, 2012 | 4.3 | 28 | NO | YES |
CVE-2022-1123HIGH The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As | Aug 29, 2022 | 7.2 | 19 | NO | NO |
CVE-2024-38782MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MapsMarker.Com e.U. Leaflet Maps Marker allows Stored XSS.This issue af | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2022-4677MEDIUM The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to pe | Feb 6, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mapsmarker.
Media articles that mention a CVE ID that affects a product developed by Mapsmarker — matched by CVE ID, not by vendor name.