Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.23% | — | Wpchill Modula Image Gallery | 3/4/2025 | 17/6/2026 | The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.1) | 0.58% | — | Needyamin Image Gallery Management System | 27/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (5.3) | 0.52% | — | Needyamin Image Gallery Management System | 27/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (7.5) | 0.83% | — | Image Gallery BOX BY CrudlabAI | 22/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CRUDLab Image Gallery Box by CRUDLab image-gallery-box-by-crudlab allows PHP Local File Inclusion.This issue affects Image Gallery Box by CRUDLab: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.1) | 0.33% | — | Image Gallery Responsive Photo GalleryAI | 15/1/2025 | 17/6/2026 | The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'awsmgallery' parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Alta (8.8) | 0.86% | — | Wpchill Modula Image Gallery | 8/1/2025 | 17/6/2026 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (6.5) | 0.35% | — | Pluginspoint Justified Image GalleryAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Justified Image Gallery justified-image-gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.3) | 1.0% | 💥 PoC | Nabajit ROY Nabz Image GalleryAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery nabz-image-gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through <= v1.00. | |
| Aplazada | Alta (7.5) | 0.83% | — | Total-soft Portfolio Gallery Responsive Image GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6. | |
| Aplazada | Media (5.3) | 0.58% | — | Wponsupport WP OnsupportAIEssentialplugin Album AND Image Gallery Plus LightboxAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Album and Image Gallery plus Lightbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Album and Image Gallery plus Lightbox: from n/a through 1.6.2. | |
| Aplazada | Media (6.5) | 0.24% | — | Skybootstrap Elementor Image Gallery PluginAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SkyBootstrap Elementor Image Gallery Plugin skyboot-portfolio-gallery allows Stored XSS.This issue affects Elementor Image Gallery Plugin: from n/a through <= 1.0.5. | |
| Modificada | Media (6.1) | 0.29% | — | Coralwebdesign CWD 3D Image Gallery | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D Image Gallery cwd-3d-image-gallery allows Reflection Injection.This issue affects CWD 3D Image Gallery: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Limbcode Limb Image GalleryAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7. | |
| Aplazada | Media (6.5) | 0.53% | — | Limbcode Limb Image GalleryAI | 16/10/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7. | |
| Aplazada | Media (4.3) | 0.40% | — | RBS Image GalleryAI | 8/10/2024 | 17/6/2026 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Analizada | Media (6.8) | 0.33% | — | Codepeople Smart Image Gallery | 13/7/2024 | 17/6/2026 | The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Media (6.4) | 0.27% | — | RBS Image GalleryAI | 19/6/2024 | 17/6/2026 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Alta (8.8) | 0.29% | — | RBS Image GalleryAI | 19/6/2024 | 17/6/2026 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' functions. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.36% | — | Awplife Image Gallery | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through 1.4.5. | |
| Modificada | Alta (7.3) | 0.48% | — | Essentialplugin Album AND Image Gallery Plus Lightbox | 6/6/2024 | 17/6/2026 | The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.91% | — | Photo Gallery Responsive Photo Gallery Image Gallery Portfolio Gallery Logo Gallery AND Team GalleryAI | 2/5/2024 | 17/6/2026 | The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.2 via deserialization via shortcode of untrusted input from the 'awl_lg_settings_' attribute. This makes it… | |
| Aplazada | Media (6.5) | 0.35% | — | Portfolio Gallery Image Gallery PluginAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portfolio Gallery – Image Gallery Plugin allows Stored XSS.This issue affects Portfolio Gallery – Image Gallery Plugin: from n/a through 1.5.6. | |
| Modificada | Crítica (9.8) | 2.0% | — | Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP | 16/3/2023 | 17/6/2026 | Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. | |
| Modificada | Media (5.3) | 0.48% | — | Wpchill Customizable Wordpress Gallery Plugin - Modula Image Gallery | 18/11/2022 | 17/6/2026 | Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress. | |
| Modificada | Alta (8.8) | 0.97% | 💥 PoC | Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP | 17/11/2022 | 17/6/2026 | A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page. |