Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
1355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.46% | — | Ays-pro Photo Gallery | 12/6/2023 | 17/6/2026 | The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.8) | 0.37% | — | Galleryplugins Video Contest | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Photo Gallery Slideshow & Masonry Tiled Gallery | 9/6/2023 | 17/6/2026 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (6.1) | 0.57% | — | 10web Photo Gallery | 7/6/2023 | 17/6/2026 | The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693. | |
| Modificada | Media (4.3) | 0.61% | — | Robogallery Gallery Images APE | 7/6/2023 | 17/6/2026 | The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site functionality or security. | |
| Modificada | Alta (8.8) | 0.26% | — | Codeixer Product Gallery Slider FOR Woocommerce | 29/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions. | |
| Modificada | Crítica (9.8) | 0.71% | — | Huge-it Portfolio Gallery | 28/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 is able to address this issue. The identifier of the patch is… | |
| Modificada | Alta (8.8) | 0.26% | — | Hmplugin Wordpress Books Gallery | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Robosoft Robogallery | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.11 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Gallery Metabox Project Gallery Metabox | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions. | |
| Modificada | Crítica (9.8) | 0.72% | — | Simple Photo Gallery Project Simple Photo Gallery | 17/5/2023 | 17/6/2026 | A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability. | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Fooplugins Foogallery | 16/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. | |
| Modificada | Media (5.4) | 0.36% | — | File Gallery Project File Gallery | 16/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5.3 versions. | |
| Modificada | Media (6.1) | 0.56% | — | I13websolution Video Gallery | 16/5/2023 | 17/6/2026 | The Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (4.8) | 0.37% | — | Simple Portfolio Gallery Project Simple Portfolio Gallery | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Greentreelabs Circles Gallery | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GreenTreeLabs Circles Gallery plugin <= 1.0.10 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Total-soft Video Gallery | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Metaslider Slider, Gallery, AND Carousel | 17/4/2023 | 17/6/2026 | The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.9) | 0.78% | — | 10web Photo Gallery | 17/4/2023 | 17/6/2026 | - The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector. | |
| Modificada | Alta (8.8) | 0.87% | — | Bestwebsoft Gallery | 17/4/2023 | 17/6/2026 | The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed… | |
| Modificada | Media (5.4) | 0.44% | — | Bestwebsoft Gallery | 17/4/2023 | 17/6/2026 | The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role. | |
| Modificada | Media (6.1) | 0.55% | — | Fancy Gallery Project Fancy Gallery | 10/4/2023 | 17/6/2026 | A vulnerability was found in Fancy Gallery Plugin 1.5.12 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file class.options.php of the component Options Page. The manipulation leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (5.4) | 0.48% | — | Robogallery Robo Gallery | 7/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-site Scripting (XSS) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.12 versions. | |
| Modificada | Media (6.1) | 0.42% | — | Wpdevart Image AND Video Gallery With Thumbnails | 29/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions. | |
| Modificada | Alta (8.1) | 0.73% | — | Simplygallery Simply Gallery Blocks With Lightbox | 27/3/2023 | 17/6/2026 | The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a… |