Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Photonic Gallery AND Lightbox FOR Flickr Smugmug AND OthersAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | |
| Aplazada | Media (6.1) | 0.27% | — | Document GalleryAI | 27/7/2026 | 27/7/2026 | The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users. | |
| Aplazada | Media (6.5) | 0.22% | — | Photo GalleryAI | 23/7/2026 | 23/7/2026 | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpchill Modula Image GalleryAI | 23/7/2026 | 23/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. | |
| Aplazada | Alta (7.1) | 0.41% | — | Videowhisper Picture GalleryAI | 23/7/2026 | 23/7/2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | |
| Aplazada | Media (5.9) | 0.24% | — | Supsystic Photo GalleryAI | 23/7/2026 | 23/7/2026 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. | |
| Aplazada | Media (5.4) | 0.23% | — | Ultimate Before After Image Slider AND GalleryAI | 14/7/2026 | 29/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level… | |
| Aplazada | Alta (7.1) | 0.25% | — | DAN Rossiter Document GalleryAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0. | |
| Aplazada | Media (6.4) | 0.45% | — | Simply Gallery BlockAI | 11/7/2026 | 13/7/2026 | The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2. This is due to insufficient input sanitization and output escaping on the sliderMaxHeight block attribute in the pgc_sgb_render_callback() function.… | |
| Aplazada | Media (6.4) | 0.42% | — | ALL IN ONE Video GalleryAI | 10/7/2026 | 10/7/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from… | |
| Aplazada | Media (6.4) | 0.26% | — | Tinywebgallery Advanced IframeAI | 8/7/2026 | 8/7/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.22% | — | Mosaic Gallery Advanced GalleryAI | 2/7/2026 | 2/7/2026 | Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | |
| Aplazada | Media (4.4) | 0.34% | 💥 PoC | Product Video Gallery FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop… | |
| Aplazada | Alta (8.5) | 0.36% | — | Contest-gallery Contest GalleryAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in Contest Gallery <= 30.0.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | GalleryAI | 26/6/2026 | 29/6/2026 | Contributor SQL Injection in Gallery <= 4.7.8 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Terrywcarter Kissgallery | 19/6/2026 | 21/8/2026 | Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information. | |
| Aplazada | Media (6.4) | 0.20% | — | Slideshow Gallery LiteAI | 18/6/2026 | 18/6/2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.40% | — | Contest-gallery Contest GalleryAI | 17/6/2026 | 17/6/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level —… | |
| Aplazada | Media (6.5) | 0.33% | — | Envira Photo GalleryAI | 16/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Inpost GalleryAI | 16/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpchill Modula Image GalleryAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Contest-gallery Contest GalleryAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. |