Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.39% | — | Ordasoft Osgallery SearchAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a… | |
| Aplazada | Baja (2.7) | 0.32% | — | Meowapps Meow GalleryAI | 20/9/2026 | 21/9/2026 | The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and… | |
| Aplazada | Media (6.5) | 0.15% | — | Meowapps Meow GalleryAI | 20/9/2026 | 21/9/2026 | The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site. | |
| Aplazada | Media (4.2) | 0.19% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging… | |
| Aplazada | Baja (2.7) | 0.30% | — | Photo Gallery Sliders Proofing ANDAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including… | |
| Aplazada | Alta (7.2) | 0.50% | — | Photo Gallery Sliders Proofing WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator… | |
| Aplazada | Media (6.5) | 0.55% | — | 10web Photo GalleryAI | 18/9/2026 | 18/9/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (8.1) | 0.54% | — | Filter GalleryAI | 18/9/2026 | 18/9/2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (4.3) | 0.39% | — | Filter GalleryAI | 18/9/2026 | 18/9/2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.34% | — | Filter GalleryAI | 18/9/2026 | 18/9/2026 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored… | |
| Aplazada | Media (6.4) | 0.26% | — | 10web Photo GalleryAI | 17/9/2026 | 17/9/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.79% | — | Contest-gallery Contest GalleryAI | 16/9/2026 | 16/9/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for… | |
| Aplazada | Media (6.3) | 0.50% | — | JoomgalleryAI | 15/9/2026 | 19/9/2026 | Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration. | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester College Notes Gallery Management SystemAI | 15/9/2026 | 15/9/2026 | A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester College Notes Gallery Management SystemAI | 15/9/2026 | 15/9/2026 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester College Notes Gallery Management SystemAI | 15/9/2026 | 15/9/2026 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.25% | — | Gallery Private Photo VaultAI | 14/9/2026 | 18/9/2026 | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage. | |
| Aplazada | Media (6.4) | 0.42% | — | Fooplugins FoogalleryAI | 5/9/2026 | 8/9/2026 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (6.8) | 0.43% | — | Catfolders Document Gallery PDF LibraryAI | 5/9/2026 | 8/9/2026 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected… | |
| Aplazada | Media (6.5) | 0.22% | — | Gallery PhotoblocksAI | 2/9/2026 | 3/9/2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | |
| Aplazada | Alta (7.1) | 0.20% | — | 10web Photo GalleryAI | 2/9/2026 | 3/9/2026 | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in… | |
| Aplazada | Media (6.8) | 0.29% | — | Codeinwp Ultimate Before After Image Slider AND GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including… | |
| Aplazada | Media (6.8) | 0.29% | — | Ultimate Before After Image Slider GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an… |