VYPR

mercator

by Sourcentis

CVEs (3)

  • CVE-2026-49344HigJun 19, 2026
    risk 0.46cvss epss 0.00

    Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts a JSON DSL (`from` / `select` / `filters` / `traverse` / `output`), translates it into an Eloquent…

  • CVE-2026-49345MedJun 19, 2026
    risk 0.35cvss epss 0.01

    Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery (SSRF) vulnerability exists in Mercator's CVE configuration panel (`/admin/config/parameters`). The `testProvider()` method in…

  • CVE-2026-27639MedFeb 25, 2026
    risk 0.00cvss 5.4epss 0.00

    Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Scripting (XSS) vulnerability exists in Mercator prior to version 2026.02.22 due to the use of unescaped Blade directives (`{!! !!}`) in display templates. An…