Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.92% | — | Remyandrade Modern Image Gallery APP | 8/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.5) | 0.56% | — | Home-gallery Homegallery | 6/3/2026 | 17/6/2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the application does not verify whether the requested file is located within the media source directory, which can result in sensitive system files being… | |
| Aplazada | Media (6.1) | 0.24% | — | ALL IN ONE Video GalleryAI | 4/3/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.4) | 0.24% | — | Enviragallery Envira GalleryAI | 4/3/2026 | 17/6/2026 | The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_gallery_theme' parameter in all versions up to, and including, 1.12.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Alta (7.5) | 0.97% | 💥 Exploit | Contest-gallery Contest GalleryAI | 2/3/2026 | 17/6/2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (5.5) | 0.59% | — | Projectworlds Online ART Gallery Shop | 2/3/2026 | 17/6/2026 | A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (5) | 0.24% | — | Responsive Lightbox GalleryAI | 25/2/2026 | 17/6/2026 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host comparison in the `ajax_upload_image()` function. This makes it possible… | |
| Aplazada | Alta (8.8) | 0.27% | — | Responsive Lightbox GalleryAI | 24/2/2026 | 17/6/2026 | The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved. | |
| Analizada | Baja (2.1) | 0.48% | — | Remyandrade Modern Image Gallery APP | 24/2/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (8.8) | 0.36% | — | WP Life Image Gallery Lightbox Gallery Responsive Photo Gallery Masonry GalleryAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-gallery allows Object Injection.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through <= 1.6.0. | |
| Aplazada | Media (5.9) | 0.25% | — | 10web Photo GalleryAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.38. | |
| Aplazada | Media (6.5) | 0.23% | — | Tinywebgallery Advanced IframeAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpchill Image Photo Gallery Final Tiles GridAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.10. | |
| Aplazada | Media (4.3) | 0.19% | — | Fooplugins FoogalleryAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11. | |
| Aplazada | Media (5.9) | 0.17% | — | Fooplugins FoogalleryAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGallery: from n/a through <= 3.1.11. | |
| Aplazada | Media (6.4) | 0.32% | — | Essentialplugin Album AND Image Gallery Plus LightboxAI | 19/2/2026 | 17/6/2026 | The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `aigpl-gallery-album` shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.39% | — | WP Audio GalleryAI | 19/2/2026 | 17/6/2026 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.28% | — | Navz ACF Photo Gallery FieldAI | 19/2/2026 | 17/6/2026 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "acf_photo_gallery_edit_save" function in all versions up to, and including, 3.0. This makes it possible for authenticated attackers, with subscriber level access and above, to… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpchill Modula Image GalleryAI | 14/2/2026 | 17/6/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API. This makes it… | |
| Aplazada | Alta (7.5) | 0.52% | — | Photostack GalleryAI | 14/2/2026 | 17/6/2026 | The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.24% | — | Gallery BY FoogalleryAI | 11/2/2026 | 17/6/2026 | The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve… | |
| Aplazada | Media (4.3) | 0.23% | — | Contest-gallery Contest GalleryAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1. | |
| Aplazada | Media (4.3) | 0.23% | — | Wpchill Modula Image GalleryAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image Gallery: from n/a through <= 2.13.6. | |
| Aplazada | Media (4.4) | 0.24% | — | Metabox GallerymetaAI | 24/1/2026 | 17/6/2026 | The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject… | |
| Aplazada | Media (4.3) | 0.22% | — | Metabox GallerymetaAI | 24/1/2026 | 17/6/2026 | The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mb_gallery' custom post type in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Author-level access and above, to create and… |