Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.54% | — | Modula Image GalleryAI | 15/6/2026 | 17/6/2026 | Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | |
| Aplazada | Alta (8.7) | 0.64% | — | HB Audio Gallery LiteAI | 15/6/2026 | 17/6/2026 | WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access sensitive files… | |
| Aplazada | Media (4.3) | 0.21% | — | Meowapps Meow GalleryAI | 13/6/2026 | 23/7/2026 | The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above,… | |
| Aplazada | Media (6.4) | 0.33% | — | Fooplugins FoogalleryAI | 13/6/2026 | 23/7/2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, which blocks only a subset of… | |
| Aplazada | Alta (8.7) | 0.64% | — | MAC Photo GalleryAI | 9/6/2026 | 21/7/2026 | Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin… | |
| Aplazada | Alta (8.8) | 0.29% | — | Apptha Slider GalleryAI | 9/6/2026 | 21/7/2026 | Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information… | |
| Aplazada | Alta (8.7) | 0.64% | — | Apptha Slider GalleryAI | 9/6/2026 | 21/7/2026 | Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory. | |
| Aplazada | Alta (8.8) | 0.26% | — | Pica Photo GalleryAI | 9/6/2026 | 21/7/2026 | WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database… | |
| Aplazada | Media (6.5) | 0.55% | — | 10web Photo GalleryAI | 6/6/2026 | 23/7/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Baja (2.1) | 0.30% | — | Projectworlds Online ART Gallery ShopAI | 4/6/2026 | 22/7/2026 | A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument social_twitter results in sql injection. The attack may be launched remotely. The exploit has been released to the… | |
| Aplazada | Baja (2.1) | 0.30% | — | Projectworlds Online ART Gallery Shop ProjectAI | 4/6/2026 | 22/7/2026 | A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be… | |
| Aplazada | Alta (7.6) | 0.38% | — | Photo Gallery BY 10webAI | 4/6/2026 | 22/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41. | |
| Aplazada | Media (5.4) | 0.24% | — | Tiled Gallery Carousel Without JetpackAI | 2/6/2026 | 22/7/2026 | The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor… | |
| Aplazada | Alta (8.8) | 0.34% | — | Joomla JE Photo GalleryAI | 1/6/2026 | 22/7/2026 | Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Wasiliy Strecker Contest Gallery PROAI | 1/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1. | |
| Aplazada | Media (6.5) | 0.55% | — | 10web Photo GalleryAI | 28/5/2026 | 17/6/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.4) | 0.32% | — | PostcategorygalleryAI | 27/5/2026 | 17/6/2026 | The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (such as total_width,… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds Online ART Gallery ShopAI | 24/5/2026 | 23/7/2026 | A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation of the argument social_linked can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (4.3) | 0.27% | — | Wpchill Image Photo Gallery Final Tiles GridAI | 20/5/2026 | 24/7/2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Nextgen GalleryAI | 20/5/2026 | 23/7/2026 | NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'. The root cause is an insufficient sanitization function ('_clean_column()') in the data mapper layer that uses a character… | |
| Aplazada | Media (4.3) | 0.26% | — | Nextgen GalleryAI | 20/5/2026 | 24/7/2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE… | |
| Aplazada | Alta (7.5) | 0.51% | — | Contest-gallery Contest GalleryAI | 19/5/2026 | 17/6/2026 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | Envira Gallery LiteAI | 14/5/2026 | 17/6/2026 | The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in the update_gallery_data() function and improper output escaping in the gallery_init() function. The… | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress Picture GalleryAI | 10/5/2026 | 25/7/2026 | WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options that are stored in the database and… | |
| Aplazada | Media (5.1) | 0.19% | — | Filterable Portfolio GalleryAI | 10/5/2026 | 25/7/2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed,… |