Filtered by vendor Mapsvg Subscriptions
Filtered by product Mapsvg Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-54669 2 Mapsvg, Wordpress 2 Mapsvg, Wordpress 2025-08-16 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG allows SQL Injection. This issue affects MapSVG: from n/a through n/a.
CVE-2024-9544 2 Mapsvg, Wordpress 2 Mapsvg, Wordpress 2025-07-13 6.4 Medium
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVE-2025-47559 2 Mapsvg, Wordpress 2 Mapsvg, Wordpress 2025-06-17 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server. This issue affects MapSVG: from n/a through 8.5.32.
CVE-2022-0592 1 Mapsvg 1 Mapsvg 2024-11-21 9.8 Critical
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.