Mapsvg
by WordPress
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65450 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-65449 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-59526 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-1771 | Hig | 0.00 | 7.2 | 0.01 | Jul 21, 2026 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This… |
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 7.2epss 0.01
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This…
Page 2 of 2