Extension WordPress

Vulnérabilités MapSVG – Vector maps, Image maps, Google Maps

Cette page rassemble les failles publiées pour MapSVG – Vector maps, Image maps, Google Maps, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de MapSVG – Vector maps, Image maps, Google Maps

8 fiches

CVE-2026-1771 Élevée · 7,2
MapSVG – Vector maps, Image maps, Google Maps

MapSVG <= 8.14.0 – Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that…

Versions affectées

*-8.14.0

Correctif

8.14.1

Publication

20/07/2026

CVE-2025-62930 Moyenne · 6,4
MapSVG – Vector maps, Image maps, Google Maps

MapSVG <= 8.7.23 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.7.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-8.7.22

Correctif

8.7.23

Publication

06/10/2025

CVE-2025-32683 Moyenne · 6,4
MapSVG – Vector maps, Image maps, Google Maps

MapSVG Lite <= 8.6.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MapSVG Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-8.6.6

Correctif

8.6.7

Publication

09/04/2025

CVE-2019-1000003 Moyenne · 6,1
MapSVG – Vector maps, Image maps, Google Maps

MapSVG Lite < 3.3.0 – Cross-Site Request Forgery

MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker modifying post data, including embedding javascript. This attack appears to be exploitable via a victim…

Versions affectées

[*, 3.3.0)

Correctif

3.3.0

Publication

08/01/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités