Mayan EDMS is a document management and workflow system with a concentrated vulnerability footprint centered on its core platform product. The durable exposure reflects the application's role as a web-facing content-handling system that processes user-supplied documents and manages access permissions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mayan Edms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14692MEDIUM A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes open redirect. It is possible t | Dec 15, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-14691MEDIUM A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. | Dec 14, 2025 | 6.1 | 22 | NO | NO |
CVE-2018-16407MEDIUM An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled. | Sep 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16406MEDIUM An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label. | Sep 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16405MEDIUM An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS. | Sep 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2022-47419MEDIUM An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system. | Feb 7, 2023 | 5.4 | 20 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web s | May 27, 2014 | 3.5 | 20 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mayan Edms.
Media articles that mention a CVE ID that affects a product developed by Mayan Edms — matched by CVE ID, not by vendor name.