Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.19% | — | Filterable Portfolio GalleryAI | 10/5/2026 | 25/7/2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed,… | |
| Aplazada | Media (5.3) | 0.46% | — | NovagalleryAI | 8/5/2026 | 17/6/2026 | novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1. | |
| Aplazada | Media (5.3) | 0.42% | — | HM Books GalleryAI | 24/4/2026 | 17/6/2026 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the admin_init hook that handles the permalink settings update at line 205-209 of wp-books-gallery.php. The vulnerable code… | |
| Aplazada | Media (6.4) | 0.33% | — | Easy Social Photos GalleryAI | 22/4/2026 | 17/6/2026 | The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class' shortcode attribute of the 'my-instagram-feed' shortcode in all versions up to, and including, 3.1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Pendiente de análisis | Crítica (9.6) | 0.82% | — | Nuget GalleryAI | 14/4/2026 | 24/7/2026 | NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a crafted nuspec file with malicious metadata, leading to cross package metadata injection that may result in remote… | |
| Aplazada | Media (6.4) | 0.51% | — | Robogallery Robo GalleryAI | 8/4/2026 | 24/7/2026 | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. The plugin uses a custom `|***...***|` marker pattern in its `fixJsFunction()` method to embed raw JavaScript function references within JSON-encoded… | |
| Aplazada | Baja (2.7) | 0.28% | — | WP Chill Image Photo Gallery Final Tiles Grid Gallery LiteAI | 8/4/2026 | 24/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11. | |
| Aplazada | Crítica (9.9) | 0.45% | — | Simplygallery Simply Gallery BlockAI | 25/3/2026 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Wasiliy Strecker Contest GalleryAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2. | |
| Aplazada | Media (6.4) | 0.16% | — | Wasiliy Strecker Contest GalleryAI | 25/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.1.2.1. | |
| Aplazada | Media (6.5) | 0.30% | — | Ruhul Amin MY Album GalleryAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Ruhul Amin My Album Gallery my-album-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Album Gallery: from n/a through <= 1.0.4. | |
| Aplazada | Media (6.4) | 0.32% | — | Easy Image GalleryAI | 25/3/2026 | 17/6/2026 | The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up to, and including, 1.5.3. This is due to insufficient input sanitization and output escaping on user-supplied gallery shortcode values. This makes it possible for… | |
| Aplazada | Alta (8.1) | 0.73% | — | Contest-gallery Contest GalleryAI | 24/3/2026 | 17/6/2026 | The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID =… | |
| Aplazada | Alta (8.8) | 0.45% | — | Nextgen GalleryAI | 18/3/2026 | 17/6/2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include… | |
| Aplazada | Alta (7.6) | 0.38% | — | Jordymeow Meow GalleryAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Blind SQL Injection.This issue affects Meow Gallery: from n/a through <= 5.4.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Robosoft Robo GalleryAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows DOM-Based XSS.This issue affects Robo Gallery: from n/a through <= 5.1.2. | |
| Aplazada | Media (4.3) | 0.14% | — | 10web Photo GalleryAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request Forgery.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37. | |
| Analizada | Alta (8.8) | 0.39% | — | Xooscripts Xoogallery | 12/3/2026 | 17/6/2026 | XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to bypass authentication, extract sensitive data, or modify database… | |
| Analizada | Alta (8.8) | 0.39% | — | Xooscripts Xoogallery | 12/3/2026 | 17/6/2026 | XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to cat.php with malicious cat_id values to bypass authentication, extract sensitive data, or modify database… | |
| Analizada | Alta (8.8) | 0.36% | — | Xooscripts Xoogallery | 12/3/2026 | 17/6/2026 | XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or… | |
| Analizada | Alta (8.8) | 0.29% | — | Xooscripts Xoogallery | 12/3/2026 | 17/6/2026 | XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. Attackers can send GET requests to gal.php with malicious gal_id values to extract sensitive database information or modify database… | |
| Aplazada | Alta (8.7) | 0.67% | — | Coppermine Photo GalleryAI | 11/3/2026 | 17/6/2026 | Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28. | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 8/3/2026 | 17/6/2026 | A security vulnerability has been detected in projectworlds Online Art Gallery Shop 1.0. This affects an unknown part of the file /admin/adminHome.php. Such manipulation of the argument reach_nm leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 8/3/2026 | 17/6/2026 | A weakness has been identified in projectworlds Online Art Gallery Shop 1.0. Affected by this issue is some unknown functionality of the file /admin/adminHome.php. This manipulation of the argument Info causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the… | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in projectworlds Online Art Gallery Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /?pass=1. The manipulation of the argument fnm results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be… |