浏览 255+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-6236 | Posts map <= 0.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute | lucdecri | Posts map | Medium | 6.4 | 2026-04-22 07:45:42 | Deep Dive |
| CVE-2026-5451 | Extensions for Leaflet Map <= 4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'elevation-track' Shortcode | hupe13 | Extensions for Leaflet Map | Medium | 6.4 | 2026-04-08 20:25:10 | Deep Dive |
| CVE-2026-39646 | WordPress Leaflet Map plugin <= 3.4.4 - Cross Site Scripting (XSS) vulnerability | bozdoz | Leaflet Map | - | - | 2026-04-08 08:30:33 | Deep Dive |
| CVE-2026-4389 | DSGVO snippet for Leaflet Map and its Extensions <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'unset' Attribute | hupe13 | DSGVO snippet for Leaflet Map and its Extensions | Medium | 6.4 | 2026-03-26 04:28:49 | Deep Dive |
| CVE-2026-4161 | Review Map by RevuKangaroo <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings | revukangaroo | Review Map by RevuKangaroo | Medium | 4.4 | 2026-03-21 03:27:07 | Deep Dive |
| CVE-2025-68002 | WordPress Open User Map plugin <= 1.4.16 - Arbitrary File Download vulnerability | 100plugins | Open User Map | Medium | 6.5 | 2026-02-20 15:46:34 | Deep Dive |
| CVE-2026-1096 | Best-wp-google-map <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'latitude' Shortcode Attribute | raju_ahmed | Best-wp-google-map | Medium | 6.4 | 2026-02-14 06:42:33 | Deep Dive |
| CVE-2026-0521 | Reflected Cross-Site Scripting in PDF Export Error Message | TYDAC AG | MAP+ | - | - | 2026-02-06 06:17:02 | Deep Dive |
| CVE-2025-14057 | Multi-column Tag Map <= 17.0.39 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'mctm_css_conditional' Parameter | tugbucket | Multi-column Tag Map | Medium | 4.4 | 2026-01-07 09:21:06 | Deep Dive |
| CVE-2025-13519 | SVG Map Plugin <= 1.0.0 - Cross-Site Request Forgery to Settings Update and Stored Cross-Site Scripting | smjrifle | SVG Map by Smjrifle | Medium | 6.1 | 2026-01-07 08:21:52 | Deep Dive |
| CVE-2025-13850 | LS Google Map Router <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | ladislavsoukupgmailcom | LS Google Map Router | Medium | 6.4 | 2025-12-12 03:21:01 | Deep Dive |
| CVE-2025-13846 | Easy Map Creator <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | qrevo | Easy Map Creator | Medium | 6.4 | 2025-12-12 03:20:48 | Deep Dive |
| CVE-2025-66098 | WordPress Travelers' Map plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerability | Camille V | Travelers' Map | Medium | 6.5 | 2025-11-21 12:30:01 | Deep Dive |
| CVE-2025-66093 | WordPress Extensions for Leaflet Map plugin <= 4.8 - Cross Site Scripting (XSS) vulnerability | hupe13 | Extensions for Leaflet Map | Medium | 6.5 | 2025-11-21 12:29:59 | Deep Dive |
| CVE-2025-48078 | WordPress Slick Google Map plugin <= 0.3 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | Norbert | Slick Google Map | High | 7.1 | 2025-11-06 15:53:37 | Deep Dive |
| CVE-2025-12369 | Extensions for Leaflet Map <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | hupe13 | Extensions for Leaflet Map | Medium | 6.4 | 2025-11-04 04:27:17 | Deep Dive |
| CVE-2020-36853 | 10WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change | 10web | 10Web Map Builder for Google Maps | High | 7.2 | 2025-10-18 03:33:24 | Deep Dive |
| CVE-2025-11365 | WP Google Map Plugin <= 1.0 - Authenticated (Contributor+) SQL Injection | akbrohi | WP Google Map Plugin | Medium | 6.5 | 2025-10-15 08:25:59 | Deep Dive |
| CVE-2025-60146 | WordPress Map Categories to Pages Plugin <= 1.3.2 - Cross Site Scripting (XSS) Vulnerability | Amit Verma | Map Categories to Pages | Medium | 5.9 | 2025-09-26 08:31:50 | Deep Dive |
| CVE-2025-57953 | WordPress Open User Map Plugin <= 1.4.14 - Cross Site Scripting (XSS) Vulnerability | 100plugins | Open User Map | Medium | 6.5 | 2025-09-22 18:24:50 | Deep Dive |