Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.59%—Rich-web Image Gallery27/6/202217/6/2026
The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)0.76%—Duogeek Simple Image Gallery14/12/202117/6/2026
The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.
ModificadaCrítica (9.8)1.5%—Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP16/8/202117/6/2026
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
ModificadaMedia (5.4)1.0%—Wpchill Modula Image Gallery20/2/202017/6/2026
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
ModificadaCrítica (9.8)2.4%—Huge-it Image Gallery21/1/202017/6/2026
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
ModificadaMedia (6.1)0.65%—Kubik-rubik Simple Image Gallery Extended5/3/201817/6/2026
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
ModificadaMedia (6.1)2.2%💥 ExploitKubik-rubik Simple Image Gallery Extended20/2/201817/6/2026
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.
ModificadaCrítica (9.8)3.2%—Wpdevart Responsive Image Gallery Gallery Album25/9/201717/6/2026
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
ModificadaCrítica (9.8)3.4%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
ModificadaMedia (5.4)0.98%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
ModificadaMedia (6.5)3.0%—Jenkins Image Gallery9/2/201717/6/2026
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
ModificadaAlta (7.5)2.3%—Wptf-image-gallery Project Wptf-image-gallery6/10/201617/6/2026
Remote file download vulnerability in wptf-image-gallery v1.03
ModificadaMedia (6.5)2.3%💥 ExploitHuge-it Image Gallery22/9/201417/6/2026
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
ModificadaAlta (7.5)1.4%—Yuriy V Semenikhin YVS Image Gallery6/10/201216/6/2026
Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into functions/db_connect.php via unspecified vectors. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation…
ModificadaMedia (4.3)1.2%—Yuriy V Semenikhin YVS Image Gallery6/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.1%—Obsession-design Image-gallery16/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
ModificadaAlta (7.5)0.99%💥 ExploitElkagroup Image Gallery5/1/201016/6/2026
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.
ModificadaMedia (4.3)1.4%💥 ExploitPlohni AN Image Gallery24/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaMedia (5)2.7%💥 ExploitPlohni AN Image Gallery24/9/200916/6/2026
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
ModificadaAlta (7.5)2.2%💥 ExploitKoschtit Image Gallery1/5/200916/6/2026
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php in ki_base/.
ModificadaMedia (6.5)3.4%💥 ExploitElkagroup Image Gallery27/4/200916/6/2026
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third…
ModificadaAlta (7.5)0.97%💥 ExploitSoftcomplex PHP Image Gallery18/3/200916/6/2026
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.
Orbitaley — Vulnerabilidades