Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.59% | — | Rich-web Image Gallery | 27/6/2022 | 17/6/2026 | The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 0.76% | — | Duogeek Simple Image Gallery | 14/12/2021 | 17/6/2026 | The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6. | |
| Modificada | Crítica (9.8) | 1.5% | — | Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP | 16/8/2021 | 17/6/2026 | An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app. | |
| Modificada | Media (5.4) | 1.0% | — | Wpchill Modula Image Gallery | 20/2/2020 | 17/6/2026 | A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users. | |
| Modificada | Crítica (9.8) | 2.4% | — | Huge-it Image Gallery | 21/1/2020 | 17/6/2026 | An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback(). | |
| Modificada | Media (6.1) | 0.65% | — | Kubik-rubik Simple Image Gallery Extended | 5/3/2018 | 17/6/2026 | The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Kubik-rubik Simple Image Gallery Extended | 20/2/2018 | 17/6/2026 | Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter. | |
| Modificada | Crítica (9.8) | 3.2% | — | Wpdevart Responsive Image Gallery Gallery Album | 25/9/2017 | 17/6/2026 | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php. | |
| Modificada | Crítica (9.8) | 3.4% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement. | |
| Modificada | Media (5.4) | 0.98% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database. | |
| Modificada | Media (6.5) | 3.0% | — | Jenkins Image Gallery | 9/2/2017 | 17/6/2026 | Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields. | |
| Modificada | Alta (7.5) | 2.3% | — | Wptf-image-gallery Project Wptf-image-gallery | 6/10/2016 | 17/6/2026 | Remote file download vulnerability in wptf-image-gallery v1.03 | |
| Modificada | Media (6.5) | 2.3% | 💥 Exploit | Huge-it Image Gallery | 22/9/2014 | 17/6/2026 | SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Yuriy V Semenikhin YVS Image Gallery | 6/10/2012 | 16/6/2026 | Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into functions/db_connect.php via unspecified vectors. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation… | |
| Modificada | Media (4.3) | 1.2% | — | Yuriy V Semenikhin YVS Image Gallery | 6/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Obsession-design Image-gallery | 16/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Elkagroup Image Gallery | 5/1/2010 | 16/6/2026 | SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Plohni AN Image Gallery | 24/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) index.php and (2) main.php, and the (3) show parameter to main.php. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Plohni AN Image Gallery | 24/9/2009 | 16/6/2026 | Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Koschtit Image Gallery | 1/5/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php in ki_base/. | |
| Modificada | Media (6.5) | 3.4% | 💥 Exploit | Elkagroup Image Gallery | 27/4/2009 | 16/6/2026 | Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Softcomplex PHP Image Gallery | 18/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action. |