Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | 10web Photo Gallery | 8/9/2019 | 17/6/2026 | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter. | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | 10web Photo Gallery | 8/9/2019 | 17/6/2026 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php. | |
| Modificada | Media (6.1) | 4.6% | 💥 Exploit | 10web Photo Gallery | 8/9/2019 | 17/6/2026 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php. | |
| Modificada | Alta (8.8) | 0.82% | — | 10web Photo Gallery | 30/8/2019 | 17/6/2026 | The photo-gallery plugin before 1.2.42 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 1.8% | — | Ays-pro Photo Gallery | 22/8/2019 | 17/6/2026 | The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection. | |
| Modificada | Alta (8.8) | 0.69% | — | Supsystic Photo Gallery | 22/8/2019 | 17/6/2026 | The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF. | |
| Modificada | Media (4.9) | 4.4% | — | 10web Photo Gallery | 9/8/2019 | 17/6/2026 | The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter. | |
| Modificada | Media (5.4) | 1.3% | — | 10web Photo Gallery | 9/8/2019 | 17/6/2026 | The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. | |
| Modificada | Crítica (9.8) | 4.5% | — | 10web Photo Gallery | 30/7/2019 | 17/6/2026 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php. | |
| Modificada | Media (6.1) | 0.99% | — | Coppermine-gallery Coppermine Photo Gallery | 7/5/2019 | 17/6/2026 | ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Coppermine-gallery Coppermine Photo Gallery | 16/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.86% | — | 10web Photo Gallery | 19/2/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 45% | 💥 Exploit | 10web Photo Gallery | 28/8/2017 | 17/6/2026 | Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. | |
| Modificada | Alta (7.2) | 1.6% | — | 10web Photo Gallery | 21/8/2017 | 17/6/2026 | The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter. | |
| Modificada | Media (6.8) | 0.65% | — | PHP Kobo Photo Gallery CMS Free | 22/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin.php in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Kobo Photo Gallery CMS Free | 22/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php. | |
| Modificada | Media (4.3) | 1.5% | — | Coppermine-gallery Coppermine Photo Gallery | 20/8/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in install_classic.php in Coppermine Photo Gallery (CPG) 1.5.36 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_username, (2) admin_password, (3) admin_email, (4) dbserver, (5) dbname, (6) dbuser, (7) dbpass, (8) table_prefix, or (9)… | |
| Modificada | Media (5) | 2.2% | — | Coppermine-gallery Coppermine Photo Gallery | 10/6/2015 | 17/6/2026 | Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php. | |
| Modificada | Media (5.8) | 2.1% | — | Coppermine-gallery Coppermine Photo Gallery | 27/5/2015 | 17/6/2026 | Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter. | |
| Modificada | Baja (3.5) | 1.5% | — | Coppermine-gallery Coppermine Photo Gallery | 27/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter. | |
| Modificada | Media (6.5) | 1.7% | — | 10web Photo Gallery | 2/2/2015 | 17/6/2026 | SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php. | |
| Modificada | Alta (7.5) | 2.1% | — | 10web Photo Gallery | 16/1/2015 | 17/6/2026 | SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php. | |
| Modificada | Media (6.8) | 1.0% | — | Lightbox Photo Gallery Project Lightbox Photo Gallery | 2/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2)… | |
| Modificada | Media (4.3) | 2.4% | — | Photo Gallery Plugin Project Photo Gallery Plugin | 10/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 1.6% | — | Flash Photo Gallery Project Flash Photo Gallery | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter. |