Vertigis develops geographic information systems and web-based mapping applications, with its disclosed vulnerabilities concentrating in products such as FM and WebOffice around web-layer input handling and resource-access control. The observed weakness classes—cross-site scripting, external resource references, and related input-validation issues—reflect the complexity of web-facing geospatial applications that process and display user-controlled data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vertigis over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0522HIGH A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated attackers to read arbitrary files from the server by manipulati | Apr 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2021-27374HIGH VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff auf Inhalte der WebOffice Applikation." | Feb 17, 2021 | 7.5 | 23 | NO | NO |
CVE-2026-3877MEDIUM A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by | Apr 1, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vertigis.
Media articles that mention a CVE ID that affects a product developed by Vertigis — matched by CVE ID, not by vendor name.