plugin

Osm Vulnerabilities

17 known security issues reported for the Osm WordPress plugin. Most recent disclosed Apr 8, 2026.

1 critical 1 high 7 medium

Running Osm on your site? Check whether your installed version is affected.

Scan your site free

OSM <= 6.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attribute

medium

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in all versions up to and including 6.1.15. This is due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
6.4
Affected:
up to 6.1.15
Fixed in:
6.1.16
Disclosed:
Apr 8, 2026

CVE-2026-4429 on NVD →

OSM &#8211; OpenStreetMap [osm] <= 6.1.12 (unfixed)

unknown

[en] Missing Authorization vulnerability in MiKa OSM osm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OSM: from n/a through <= 6.1.12.

Affected:
up to 6.1.12
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25323 on NVD →

OSM – OpenStreetMap <= 6.1.12 - Missing Authorization

medium

The OSM – OpenStreetMap plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.1.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 6.1.12
Fixed in:
6.1.13
Disclosed:
Jan 29, 2026

CVE-2026-25323 on NVD →

OSM – OpenStreetMap <= 6.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 6.1.13
Fixed in:
6.1.14
Disclosed:
Mar 31, 2025

CVE-2025-31557 on NVD →

OSM &#8211; OpenStreetMap [osm] <= 6.1.6 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM – OpenStreetMap allows DOM-Based XSS. This issue affects OSM – OpenStreetMap: from n/a through 6.1.6.

Affected:
up to 6.1.6
Fix:
No patched version reported
Disclosed:
Mar 31, 2025

CVE-2025-31557 on NVD →

OSM &#8211; OpenStreetMap [osm] < 6.1.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hyumika OSM – OpenStreetMap allows Stored XSS.This issue affects OSM – OpenStreetMap: from n/a through 6.1.2.

Affected:
up to 6.1.3
Fixed in:
6.1.3
Disclosed:
Nov 11, 2024

CVE-2024-52355 on NVD →

OSM – OpenStreetMap <= 6.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pa...

CVSS:
6.4
Affected:
up to 6.1.2
Fixed in:
6.1.3
Disclosed:
Nov 8, 2024

CVE-2024-52355 on NVD →

OSM &#8211; OpenStreetMap [osm] < 6.1.1

unknown

[en] The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

Affected:
up to 6.1.1
Fixed in:
6.1.1
Disclosed:
Sep 27, 2024

CVE-2024-8991 on NVD →

OSM <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via osm_map and osm_map_v3 Shortcodes

medium

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 6.1.0
Fixed in:
6.1.1
Disclosed:
Sep 26, 2024

CVE-2024-8991 on NVD →

OSM &#8211; OpenStreetMap [osm] < 6.0.4

unknown

[en] The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping on user supplied attributes such as 'theme'. This makes it possible for authenticated...

Affected:
up to 6.0.4
Fixed in:
6.0.4
Disclosed:
Jul 9, 2024

CVE-2024-3603 on NVD →

OSM &#8211; OpenStreetMap [osm] < 6.0.4

unknown

[en] The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, and including, 6.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This mak...

Affected:
up to 6.0.4
Fixed in:
6.0.4
Disclosed:
Jul 9, 2024

CVE-2024-3604 on NVD →

OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injection

critical

The OSM – OpenStreetMap plugin for WordPress is vulnerable to SQL Injection via the 'tagged_filter' attribute of the 'osm_map_v3' shortcode in all versions up to, and including, 6.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

CVSS:
9.9
Affected:
up to 6.0.3
Fixed in:
6.0.4
Disclosed:
Jul 8, 2024

CVE-2024-3604 on NVD →

OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes such as 'theme'. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 6.0.3
Fixed in:
6.0.4
Disclosed:
Jul 8, 2024

CVE-2024-3603 on NVD →

OSM &#8211; OpenStreetMap [osm] < 6.0.6

unknown

[en] The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Affected:
up to 6.0.6
Fixed in:
6.0.6
Disclosed:
May 30, 2023

CVE-2022-4676 on NVD →

OSM - OpenStreetMap <= 6.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via 'osm_map' Shortcode

medium

The OSM - OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in versions up to, and including, 6.0.5 due to insufficient input sanitization and output escaping on user supplied attributes like 'map_border'. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 6.0.5
Fixed in:
6.0.6
Disclosed:
May 3, 2023

CVE-2022-4676 on NVD →

OSM &#8211; OpenStreetMap [osm] < 6.0.1

unknown

[en] Cross-Site Request Forgery (CSRF) in MiKa's OSM – OpenStreetMap plugin <= 6.0.1 versions.

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Jan 17, 2023

CVE-2022-30544 on NVD →

OSM - OpenStreetMap <= 6.0 - Cross-Site Request Forgery

high

The OSM - OpenStreetMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted they can...

CVSS:
8.8
Affected:
up to 6.0
Fixed in:
6.0.1
Disclosed:
Sep 30, 2022

CVE-2022-30544 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database