Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.23% | — | Ogucan Ozugenc Gallery AND LightboxAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oğulcan Özügenç Gallery and Lightbox gallery-and-lightbox allows Stored XSS.This issue affects Gallery and Lightbox: from n/a through <= 1.0.14. | |
| Aplazada | Alta (7.1) | 0.33% | — | Gallery-images-apeAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gallery Ape Photo Gallery – Image Gallery by Ape gallery-images-ape allows Reflected XSS.This issue affects Photo Gallery – Image Gallery by Ape: from n/a through <= 2.2.8. | |
| Aplazada | Media (6.1) | 0.33% | — | Image Gallery Responsive Photo GalleryAI | 15/1/2025 | 17/6/2026 | The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'awsmgallery' parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Alta (8.8) | 0.86% | — | Wpchill Modula Image Gallery | 8/1/2025 | 17/6/2026 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (5.4) | 0.43% | — | Beautifultemplates ST Gallery WPAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in beautifultemplates ST Gallery WP st-gallery-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ST Gallery WP: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.35% | — | Pluginspoint Justified Image GalleryAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Justified Image Gallery justified-image-gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Bvads BVD Easy Gallery ManagerAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bvads BVD Easy Gallery Manager bvd-easy-gallery-manager allows Reflected XSS.This issue affects BVD Easy Gallery Manager: from n/a through <= 1.0.6. | |
| Analizada | Baja (2.7) | 0.53% | — | Robosoft Robo Gallery | 7/1/2025 | 17/6/2026 | The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (6.4) | 0.27% | — | WP Youtube GalleryAI | 7/1/2025 | 17/6/2026 | The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (4.3) | 0.38% | — | Photo Gallery Slideshow Masonry Tiled GalleryAI | 3/1/2025 | 17/6/2026 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justified_gallery_callback function. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (4.3) | 0.32% | — | Robogallery Gallery Images APEAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8. | |
| Modificada | Media (4.8) | 0.33% | — | Contest-gallery Contest Gallery | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Stored XSS.This issue affects Contest Gallery: from n/a through <= 24.0.3. | |
| Modificada | Media (5.4) | 0.31% | — | Wpdevart Gallery | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Ondrej Donek Od-photogallery-pluginAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ondrej Donek odPhotogallery od-photogallery-plugin allows Reflected XSS.This issue affects odPhotogallery: from n/a through <= 0.5.3. | |
| Analizada | Media (6.1) | 0.33% | — | Ulfben Exhibit TO WP Gallery | 24/12/2024 | 17/6/2026 | The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.3) | 0.56% | — | Home-galleryAI | 23/12/2024 | 17/6/2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow an attacker to view the images of home-gallery when it is using the default settings. The following express middleware allows any website to make a cross site… | |
| Aplazada | Media (5.3) | 0.28% | — | Home-galleryAI | 23/12/2024 | 17/6/2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, the default setup of home-gallery is vulnerable to DNS rebinding. Home-gallery is set up without TLS and user authentication by default, leaving it vulnerable to DNS rebinding. In this attack, an… | |
| Aplazada | Media (6.4) | 0.32% | — | Portfolio Filterable Masonry Portfolio Gallery FOR ProfessionalsAI | 17/12/2024 | 17/6/2026 | The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Crítica (9.3) | 1.0% | 💥 PoC | Nabajit ROY Nabz Image GalleryAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery nabz-image-gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through <= v1.00. | |
| Aplazada | Crítica (9.9) | 0.66% | — | Suiteplugins Video AND Photo Gallery FOR Ultimate MemberAI | 16/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.0. | |
| Aplazada | Media (4.3) | 0.69% | — | Team Plugins360 Automatic Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3. | |
| Aplazada | Media (4.3) | 0.47% | — | Mateusz Czardybon Justified GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Mateusz Czardybon Justified Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Justified Gallery: from n/a through 1.7.3. | |
| Modificada | Media (4.3) | 0.51% | — | 10web Photo Gallery | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through 1.8.15. | |
| Aplazada | Alta (7.5) | 0.83% | — | Total-soft Portfolio Gallery Responsive Image GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6. | |
| Aplazada | Alta (7.5) | 0.84% | — | Total-soft Video Gallery Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6. |