Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)25%💥 Exploit10web Photo Gallery8/9/201917/6/2026
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
ModificadaMedia (6.1)5.3%💥 Exploit10web Photo Gallery8/9/201917/6/2026
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
ModificadaMedia (6.1)4.6%💥 Exploit10web Photo Gallery8/9/201917/6/2026
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
ModificadaAlta (8.8)0.82%—10web Photo Gallery30/8/201917/6/2026
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
ModificadaCrítica (9.8)1.8%—Ays-pro Photo Gallery22/8/201917/6/2026
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
ModificadaAlta (8.8)0.69%—Supsystic Photo Gallery22/8/201917/6/2026
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
ModificadaMedia (4.9)4.4%—10web Photo Gallery9/8/201917/6/2026
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
ModificadaMedia (5.4)1.3%—10web Photo Gallery9/8/201917/6/2026
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
ModificadaCrítica (9.8)4.5%—10web Photo Gallery30/7/201917/6/2026
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
ModificadaMedia (6.1)0.99%—Coppermine-gallery Coppermine Photo Gallery7/5/201917/6/2026
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
ModificadaMedia (6.1)1.3%—Coppermine-gallery Coppermine Photo Gallery16/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.86%—10web Photo Gallery19/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)45%💥 Exploit10web Photo Gallery28/8/201717/6/2026
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
ModificadaAlta (7.2)1.6%—10web Photo Gallery21/8/201717/6/2026
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
ModificadaMedia (6.8)0.65%—PHP Kobo Photo Gallery CMS Free22/8/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in admin.php in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (4.3)1.2%—PHP Kobo Photo Gallery CMS Free22/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php.
ModificadaMedia (4.3)1.5%—Coppermine-gallery Coppermine Photo Gallery20/8/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in install_classic.php in Coppermine Photo Gallery (CPG) 1.5.36 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_username, (2) admin_password, (3) admin_email, (4) dbserver, (5) dbname, (6) dbuser, (7) dbpass, (8) table_prefix, or (9)…
ModificadaMedia (5)2.2%—Coppermine-gallery Coppermine Photo Gallery10/6/201517/6/2026
Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.
ModificadaMedia (5.8)2.1%—Coppermine-gallery Coppermine Photo Gallery27/5/201517/6/2026
Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.
ModificadaBaja (3.5)1.5%—Coppermine-gallery Coppermine Photo Gallery27/5/201517/6/2026
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.
ModificadaMedia (6.5)1.7%—10web Photo Gallery2/2/201517/6/2026
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
ModificadaAlta (7.5)2.1%—10web Photo Gallery16/1/201517/6/2026
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
ModificadaMedia (6.8)1.0%—Lightbox Photo Gallery Project Lightbox Photo Gallery2/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2)…
ModificadaMedia (4.3)2.4%—Photo Gallery Plugin Project Photo Gallery Plugin10/10/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
ModificadaMedia (4.3)1.6%—Flash Photo Gallery Project Flash Photo Gallery2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.