Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Supsystic Subscribe
Filtered by product Easy Google Maps
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46780 1 Supsystic 1 Easy Google Maps 2022-05-03 4.3 MEDIUM 6.1 MEDIUM
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
CVE-2021-39346 1 Supsystic 1 Easy Google Maps 2021-11-02 2.1 LOW 4.8 MEDIUM
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.