Tum develops web-based geographic and geospatial services, notably the Navigatum mapping platform and OGC Web Feature Service implementations, which handle user-supplied path and XML input. The vendor's observed vulnerability signal centers on path-traversal and XML-external-entity weaknesses, reflecting the input-validation demands of services that parse and resolve file paths and document structures from client requests. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tum over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4607CRITICAL A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation le | Dec 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-25575HIGH NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in the propose_edits endpoint allow | Feb 4, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tum.
Media articles that mention a CVE ID that affects a product developed by Tum — matched by CVE ID, not by vendor name.