CVE-2014-9686: Mapsplugin Googlemaps

Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.

The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7428.

Affected products

Published 2017-09-28. Last modified 2026-06-17.