Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.59%—AYS Photo GalleryAI1/9/20262/9/2026
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaBaja (2)0.35%—Coppermine-gallery Coppermine Photo GalleryAI30/8/202631/8/2026
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be…
AplazadaBaja (2)0.35%—Coppermine Photo GalleryAI30/8/20261/9/2026
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The attack can be initiated remotely. The…
AplazadaMedia (5.3)0.19%—Catfolders Document Gallery PROAI29/8/202631/8/2026
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.
AplazadaMedia (6.4)0.33%—Enviragallery Envira GalleryAI28/8/202628/8/2026
The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, 1.12.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access…
AplazadaMedia (4.8)0.24%—SOY GalleryAI28/8/202628/8/2026
SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
Pendiente de análisisCrítica (9.1)0.23%—Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI25/8/202628/8/2026
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
AplazadaMedia (6.4)0.33%—Image Photo Gallery Final Tiles GridAI22/8/202624/8/2026
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.6)0.52%💥 PoCJoomgalleryAI22/8/202626/8/2026
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.
AplazadaMedia (6.9)0.43%💥 PoCJoomgalleryAI22/8/202626/8/2026
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctly enforces the password gate - but the…
AplazadaAlta (7.1)0.25%—Lcweb Global GalleryAI19/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
AplazadaAlta (7.1)0.25%—Contest-gallery Contest GalleryAI19/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
AplazadaAlta (7.2)0.56%—Bestwebsoft GalleryAI16/8/202620/8/2026
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The…
AplazadaMedia (6.5)0.55%—Contest-gallery Contest GalleryAI15/8/202620/8/2026
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user…
AplazadaMedia (5)0.27%—Plugins360 All-in-one Video GalleryAI10/8/202626/8/2026
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
AplazadaMedia (5.4)0.23%—Meowapps Meow GalleryAI7/8/202626/8/2026
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators)…
AplazadaAlta (7.1)0.47%💥 ExploitNextgen GalleryAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
AplazadaAlta (7.5)0.42%—Contest-gallery Contest GalleryAI5/8/202626/8/2026
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin…
AplazadaMedia (4.3)0.27%—Contest-gallery Contest GalleryAI4/8/202626/8/2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.
AplazadaMedia (6.5)0.42%—Contest-gallery Contest GalleryAI3/8/202626/8/2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
AplazadaAlta (7.5)0.43%—Gallery FOR Google PhotosAI2/8/202626/8/2026
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.
AplazadaAlta (7.1)0.25%—Contest-gallery Contest GalleryAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
AplazadaMedia (6.5)0.22%—Gallery PhotoblocksAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
AplazadaMedia (6.5)0.22%—Photonic Gallery AND Lightbox FOR Flickr Smugmug AND OthersAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
AplazadaMedia (6.1)0.27%—Document GalleryAI27/7/202627/7/2026
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.