Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | Wppa WP Photo Album PlusAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wppa WP Photo Album PlusAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. | |
| Aplazada | Alta (7.5) | 0.91% | — | Wppa WP Photo Album PlusAI | 19/9/2026 | 21/9/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd()… | |
| Aplazada | Alta (7.2) | 0.29% | — | Wppa WP Photo Album PlusAI | 11/9/2026 | 11/9/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (4.3) | 0.25% | — | Wppa WP Photo Album PlusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Wppa WP Photo Album PlusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options… | |
| Aplazada | Media (6.1) | 0.26% | — | Wppa WP Photo Album PlusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page… | |
| Aplazada | Media (5.3) | 0.32% | — | Wppa WP Photo Album PlusAI | 9/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores. | |
| Aplazada | Media (6.1) | 0.25% | — | Wppa WP Photo Album PlusAI | 31/7/2026 | 26/8/2026 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by… | |
| Aplazada | Media (4.9) | 0.60% | — | Wppa WP Photo Album PlusAI | 29/7/2026 | 30/7/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wppa WP Photo Album PlusAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions. | |
| Aplazada | Media (6.4) | 0.42% | — | Wppa WP Photo Album PlusAI | 1/7/2026 | 1/7/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, 9.1.13.005 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Alta (7.5) | 0.32% | — | Wppa WP Photo Album PlusAI | 25/6/2026 | 25/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wppa WP Photo Album PlusAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. | |
| Aplazada | Alta (8.6) | 0.45% | 💥 PoC | Wppa WP Photo Album PlusAI | 18/5/2026 | 17/6/2026 | The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wppa WP Photo Album PlusAI | 7/1/2026 | 7/10/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.4) | 0.21% | — | Wppa WP Photo Album PlusAI | 4/10/2025 | 17/6/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.5) | 0.26% | — | Ghozylab Gallery - Photo Albums PluginAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery – Photo Albums Plugin easy-media-gallery allows Stored XSS.This issue affects Gallery – Photo Albums Plugin: from n/a through <= 1.3.170. | |
| Analizada | Alta (7.3) | 1.6% | 💥 PoC | Wppa WP Photo Album Plus | 10/11/2024 | 17/6/2026 | The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Media (6.1) | 0.32% | — | Wppa WP Photo Album PlusAI | 17/10/2024 | 17/6/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.19% | — | Michalaugustyniak Misiek Photo Album | 12/9/2024 | 17/6/2026 | The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Media (6.5) | 0.24% | — | Michalaugustyniak Misiek Photo Album | 12/9/2024 | 17/6/2026 | The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack | |
| Modificada | Media (6.1) | 0.33% | — | Wppa WP Photo Album Plus | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.00.002. | |
| Aplazada | Media (6.5) | 0.27% | — | Wppa WP Photo Album PlusAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.02.002. | |
| Aplazada | Media (5.3) | 0.31% | — | Wppa WP Photo Album PlusAI | 4/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005. |