org.mapfish.print:print-servlet
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.mapfish.print:print-servletpage 1 of 1
- CVE-2020-15231CRITICALCVSS 9.3EG 9.3✓ Fixed in 3.242020-10-02
vulnerable: 1.2.0 ... 3.9.0 (55 versions)
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
- CVE-2020-15232CRITICALCVSS 9.3EG 9.3✓ Fixed in 3.242020-10-02
vulnerable: 3.0 ... 3.9.0 (47 versions)
In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
- CVE-2026-44672CRITICALCVSS 9.3EG 9.3✓ Fixed in 4.0.32026-05-28
mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. T…
- CVE-2026-55848HIGHCVSS 8.6EG 8.6✓ Fixed in 3.30.322026-08-28
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpo…
Check whether org.mapfish.print:print-servlet is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.mapfish.print:print-servlet CVEs against the assets you own.
Start Free Scan →