Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mayan Edms

First CVE: May 27, 2014Active for: 12 yearsTotal CVEs: 12

Mayan EDMS is a document management and workflow system with a concentrated vulnerability footprint centered on its core platform product. The durable exposure reflects the application's role as a web-facing content-handling system that processes user-supplied documents and manages access permissions. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mayan Edms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2014
12 years ago
Most Recent CVE
Dec 15, 2025
221 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-14692MEDIUM
A flaw has been found in Mayan EDMS up to 4.10.1. The impacted element is an unknown function of the file /authentication/. This manipulation causes open redirect. It is possible t
Dec 15, 20256.122NONO
CVE-2025-14691MEDIUM
A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting.
Dec 14, 20256.122NONO
CVE-2018-16407MEDIUM
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.
Sep 3, 20186.121NONO
CVE-2018-16406MEDIUM
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.
Sep 3, 20186.121NONO
CVE-2018-16405MEDIUM
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.
Sep 3, 20186.121NONO
CVE-2022-47419MEDIUM
An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system.
Feb 7, 20235.420NONO
CVE-2014-3840LOW
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web s
May 27, 20143.520NOYES
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
86%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown1 (14.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High0 (0.0%)
Unknown1 (14.3%)
User Interaction
None0 (0.0%)
Unknown1 (14.3%)
Required6 (85.7%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None5 (71.4%)
Unknown1 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mayan Edms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mayan Edms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mayan Edms's Products

View all 3 CNAs →

Top CWEs