Extension WordPress
Vulnérabilités OSM – OpenStreetMap
Cette page rassemble les failles publiées pour OSM – OpenStreetMap, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de OSM – OpenStreetMap
9 fiches
OSM <= 6.1.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attribute
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in all versions up to and including 6.1.15. This is due to insufficient input…
*-6.1.15
6.1.16
08/04/2026
OSM – OpenStreetMap <= 6.1.12 – Missing Authorization
The OSM – OpenStreetMap plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.12. This makes it possible for authenticated attackers, with Contributor-level…
*-6.1.12
6.1.13
29/01/2026
OSM – OpenStreetMap <= 6.1.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-6.1.13
6.1.14
31/03/2025
OSM – OpenStreetMap <= 6.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-6.1.2
6.1.3
08/11/2024
OSM <= 6.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via osm_map and osm_map_v3 Shortcodes
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user…
*-6.1.0
6.1.1
26/09/2024
OSM – OpenStreetMap <= 6.0.3 – Authenticated (Contributor+) SQL Injection
The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, and including, 6.0.3 due to insufficient escaping on the user supplied parameter and…
*-6.0.3
6.0.4
08/07/2024
OSM – OpenStreetMap <= 6.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes…
*-6.0.3
6.0.4
08/07/2024
OSM – OpenStreetMap <= 6.0.5 – Authenticated(Contributor+) Stored Cross-Site Scripting via 'osm_map' Shortcode
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in versions up to, and including, 6.0.5 due to insufficient input sanitization and output escaping on user supplied attributes like…
*-6.0.5
6.0.6
03/05/2023
OSM – OpenStreetMap <= 6.0 – Cross-Site Request Forgery
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible…
*-6.0
6.0.1
30/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.