Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.62%—Webhuntinfotech Photo Video Gallery Master19/6/202417/6/2026
The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of untrusted input 'PVGM_all_photos_details' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP…
ModificadaAlta (8.8)0.64%—Yotuwp Video Gallery15/6/202417/6/2026
The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the display function. This makes it possible for authenticated attackers, with contributor access and higher, to include and execute arbitrary php…
ModificadaCrítica (9.8)0.77%—Yotuwp Video Gallery15/6/202417/6/2026
The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the settings parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…
AnalizadaAlta (8.8)0.38%—Plugins360 All-in-one Video Gallery9/6/202417/6/2026
Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2.
ModificadaMedia (5.3)0.33%—Emarketdesign Youtube Video Gallery21/5/202417/6/2026
The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it possible for…
AplazadaAlta (8.8)0.62%—ALL IN ONE Video GalleryAI15/5/202417/6/2026
The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server,…
AplazadaMedia (4.3)0.39%—WP Life Video Gallery API Gallery Youtube Vimeo Link GalleryAI6/5/202417/6/2026
Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.
AplazadaAlta (8.8)1.6%—Plugins360 All-in-one Video GalleryAI2/5/202417/6/2026
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers, with contributor access and…
ModificadaCrítica (9.8)0.55%—Total-soft Video Gallery6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.
ModificadaAlta (8.8)0.18%—Wpdevart Gallery - Image AND Video Gallery With Thumbnails16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
ModificadaAlta (8.8)0.25%—Emarketdesign Youtube Video Gallery3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions.
ModificadaMedia (4.8)0.36%—Yotuwp Video Gallery1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yotuwp Video Gallery plugin <= 1.3.12 versions.
ModificadaMedia (6.1)0.35%—I13websolution Video Gallery30/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Gallery plugin <= 1.0.10 versions.
ModificadaMedia (6.1)0.56%—I13websolution Video Gallery16/5/202317/6/2026
The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (4.8)0.37%—Total-soft Video Gallery3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.
ModificadaMedia (6.1)0.42%—Wpdevart Image AND Video Gallery With Thumbnails29/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.
ModificadaMedia (5.4)0.48%—Utubevideo Gallery Project Utubevideo Gallery13/2/202317/6/2026
The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.2)34%💥 ExploitPlugins360 All-in-one Video Gallery6/9/202217/6/2026
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on…
ModificadaCrítica (9.8)0.75%—Yotuwp Video Gallery23/8/202217/6/2026
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
ModificadaCrítica (9.8)9.1%💥 ExploitWp-video-gallery-free Project Wp-video-gallery-free9/5/202217/6/2026
The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
ModificadaAlta (7.2)5.0%💥 ExploitPlugins360 All-in-one Video Gallery13/12/202117/6/2026
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue
ModificadaMedia (4.8)0.62%—Origincode Video Gallery25/10/202117/6/2026
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues
ModificadaMedia (5.4)0.58%—Bplugins Polo Video Gallery18/10/202117/6/2026
The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
ModificadaCrítica (9.8)2.7%💥 ExploitJextn Video Gallery27/12/201717/6/2026
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
ModificadaCrítica (9.8)3.6%💥 ExploitHuge-it Video Gallery6/10/201617/6/2026
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
Orbitaley — Vulnerabilidades