Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Enviragallery Envira GalleryAI | 7/10/2026 | 7/10/2026 | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an… | |
| Recibida | Sin puntuar | — | — | Enviragallery Envira GalleryAI | 7/10/2026 | 7/10/2026 | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Gmedia Photo GalleryAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Document GalleryAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | |
| Pendiente de análisis | Media (6.3) | 0.32% | — | Svenbluege Event GalleryAI | 5/10/2026 | 6/10/2026 | Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Svenbluege.de Event GalleryAI | 5/10/2026 | 6/10/2026 | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address… | |
| Pendiente de análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 5/10/2026 | 6/10/2026 | Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting… | |
| Aplazada | Media (6.5) | 0.16% | — | Wpchill Final Tiles Grid Gallery LiteAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13. | |
| Aplazada | Media (6.1) | 0.23% | — | 10web Photo GalleryAI | 3/10/2026 | 6/10/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (8.8) | 0.29% | — | 10web Photo GalleryAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Books GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | |
| Aplazada | Alta (7.5) | 0.40% | — | Nextgen GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Responsive Slider GalleryAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. | |
| Aplazada | Media (5.4) | 0.10% | — | Supsystic Photo GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | |
| En análisis | Media (5.3) | 0.24% | — | Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated. | |
| En análisis | Alta (7) | 0.31% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | |
| En análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted. | |
| En análisis | Media (6.9) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | |
| En análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name. | |
| En análisis | Crítica (9.3) | 0.38% | 💥 PoC | Joomlaboat Youtube GalleryAI | 26/9/2026 | 29/9/2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries. | |
| Aplazada | Alta (8.1) | 0.27% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via… | |
| Aplazada | Baja (2.1) | 0.35% | — | Anirbandutta9 College-notes-galleryAI | 22/9/2026 | 23/9/2026 | A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation of the argument image results in unrestricted upload. It is possible to… | |
| Aplazada | Media (5.5) | 0.41% | — | Anirbandutta9 College-notes-galleryAI | 22/9/2026 | 23/9/2026 | A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content… |