Mapsplugin develops integrations centered on the Google Maps product, serving as a bridge between mapping functionality and web applications. Vulnerabilities affecting the vendor lean toward serious outcomes, with an elevated share reaching critical severity, and recur through web-oriented weakness classes including cross-site scripting, sensitive-information exposure, resource-consumption issues, and XML injection that reflect the data-handling and user-input demands of map-embedding code. Defenders should treat this vendor's advisories as relevant to any application that embeds its Google Maps integrations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mapsplugin over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7429CRITICAL The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php. | Sep 14, 2017 | 9.8 | 29 | NO | NO |
CVE-2013-7432HIGH The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism. | Aug 29, 2017 | 7.5 | 24 | NO | NO |
CVE-2013-7428HIGH The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php. | Sep 7, 2017 | 7.5 | 23 | NO | NO |
CVE-2014-9686MEDIUM The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' param | Sep 28, 2017 | 5.9 | 21 | NO | NO |
CVE-2013-7433MEDIUM Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!. | Aug 29, 2017 | 6.1 | 21 | NO | NO |
CVE-2013-7430MEDIUM Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter. | Aug 28, 2017 | 6.1 | 21 | NO | NO |
CVE-2013-7431MEDIUM Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!. | Aug 29, 2017 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mapsplugin.
Media articles that mention a CVE ID that affects a product developed by Mapsplugin — matched by CVE ID, not by vendor name.