Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.48% | — | Wppa WP Photo Album Plus | 24/5/2024 | 17/6/2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Crítica (10) | 0.54% | — | Wppa WP Photo Album PlusAI | 14/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001. | |
| Aplazada | Crítica (9.9) | 0.86% | — | Wppa WP Photo Album PlusAI | 7/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005. | |
| Modificada | Alta (7.5) | 0.53% | — | Wppa WP Photo Album Plus | 19/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005. | |
| Modificada | Media (6.1) | 0.39% | — | Wppa WP Photo Album Plus | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005. | |
| Analizada | Media (6.4) | 0.68% | — | Wppa WP Photo Album Plus | 14/2/2022 | 17/6/2026 | The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel. | |
| Modificada | Baja (3.5) | 1.2% | — | Ghozylab Gallery - Photo Albums - Portfolio | 28/9/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields. | |
| Modificada | Media (4.3) | 2.4% | — | Wppa.opajaap Wp-photo-album-plus | 21/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action. | |
| Modificada | Media (5.4) | 0.27% | — | Geteversnap Eversnap Private Photo Album | 9/9/2014 | 17/6/2026 | The Eversnap Private Photo Album (aka com.weddingsnap.android) application 1.0.23 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Wppa.opajaap Wp-photo-album-plus | 10/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppa_manage_comments edit action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Jayeshp Pixel8 WEB Photo Album | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Kevin Walker PHP Photo Album | 5/2/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Atomic Photo Album | 23/10/2008 | 16/6/2026 | Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Availscript Photo Album | 1/10/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Availscript Photo Album | 1/10/2008 | 16/6/2026 | SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Constantin Charissis Atomic Photo Album | 30/9/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Atomic Photo Album | 30/9/2008 | 16/6/2026 | SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wordpress Photo Album Plugin | 25/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name… | |
| Modificada | Media (4.3) | 0.84% | — | Dansie Photo Album | 16/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5.8) | 1.9% | 💥 Exploit | Php4script AZ Photo Album Script PRO | 31/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter. | |
| Modificada | Media (5) | 1.6% | — | Atomic Photo Album | 3/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Phpbb Group PhpbbSmartor Photo Album | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpbb Group PhpbbSmartor Photo Album | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | John Beatty Easy PHP Photo Album | 11/5/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. |