Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.28% | — | Tinywebgallery Advanced Iframe | 29/2/2024 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due to the plugin allowing users to include JS files from external sources through the additional_js attribute. This makes it possible for… | |
| Modificada | Media (5.4) | 0.29% | — | Tinywebgallery Advanced Iframe | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.10. | |
| Modificada | Media (5.4) | 0.31% | — | Tinywebgallery Advanced Iframe | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.8. | |
| Modificada | Media (5.4) | 0.31% | — | Tinywebgallery Advanced Iframe | 1/2/2024 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (5.4) | 0.55% | — | Tinywebgallery Advanced Iframe | 13/11/2023 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.80% | — | Tinywebgallery Advanced Iframe | 7/3/2022 | 17/6/2026 | The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.3) | 1.8% | — | Tinywebgallery | 3/2/2020 | 16/6/2026 | TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php. | |
| Modificada | Alta (7.2) | 1.4% | — | Tinywebgallery | 9/1/2020 | 16/6/2026 | PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file. | |
| Modificada | Crítica (9.8) | 3.5% | — | Tinywebgallery Wordpress Flash Uploader | 25/4/2018 | 17/6/2026 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path. | |
| Modificada | Media (5.4) | 0.78% | — | Tinywebgallery | 6/11/2017 | 17/6/2026 | In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-privilege user accounts for backend access are able to inject malicious script codes into the `TWG Explorer` item listing. The request method to inject is POST… | |
| Modificada | Media (4.3) | 1.2% | — | Tinywebgallery | 24/4/2015 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the selitems[] parameter in a (1) copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/index.php. | |
| Modificada | Media (6.8) | 0.69% | — | Tinywebgallery | 24/4/2015 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers.php via the user… | |
| Modificada | Alta (7.5) | 4.4% | — | Tinywebgallery | 9/10/2012 | 16/6/2026 | TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php. | |
| Modificada | Media (5) | 1.2% | — | Tinywebgallery | 24/9/2011 | 16/6/2026 | TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by i_frames/i_register.php. | |
| Modificada | Media (6.8) | 2.5% | — | TinywebgalleryClaudio Klingler Quixplorer | 4/6/2009 | 16/6/2026 | Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php. | |
| Modificada | Media (4.3) | 1.0% | — | Tinywebgallery | 18/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) index.php, (2) i_frames/i_login.php, and (3) i_frames/i_top_tags.php. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 3.7% | — | Tinywebgallery | 16/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2. | |
| Modificada | Media (4.3) | 1.9% | — | Tinywebgallery | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter. | |
| Modificada | Media (5) | 2.9% | — | TinywebAI | 31/12/2004 | 16/6/2026 | TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL. | |
| Modificada | Alta (7.8) | 1.7% | — | RIT Research Labs Tinyweb | 31/12/2003 | 16/6/2026 | TinyWeb 1.9 allows remote attackers to cause a denial of service (CPU consumption) via a ".%00." in an HTTP GET request to the cgi-bin directory. |