Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
1352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | ALL IN ONE Video GalleryAI | 24/1/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Media (4.3) | 0.15% | — | WP Youtube Video GalleryAI | 24/1/2026 | 17/6/2026 | The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce verification on the wpYTVideoGallerySettingSave() function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged… | |
| Analizada | Crítica (9.8) | 0.92% | — | Remyandrade Modern Image Gallery APP | 23/1/2026 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an… | |
| Aplazada | Media (6.5) | 0.41% | — | ALL IN ONE Video Gallery All-in-one-video-galleryAI | 23/1/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_callback_delete_bunny_stream_video` functions in all versions up to, and including,… | |
| Aplazada | Media (6.5) | 0.15% | — | WP Chill Gallery PhotoblocksAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows DOM-Based XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.9) | 0.20% | — | Wpchill Modula Image GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4. | |
| Aplazada | Alta (7.1) | 0.30% | — | Adamlabs Wordpress Photo GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0. | |
| Aplazada | Alta (8.5) | 0.43% | — | DZS Video GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allows SQL Injection.This issue affects DZS Video Gallery: from n/a through <= 12.39. | |
| Aplazada | Media (5.3) | 0.25% | — | 10web Photo GalleryAI | 22/1/2026 | 17/6/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Media (5.4) | 0.22% | — | Image Photo Gallery Final Tiles GridAI | 20/1/2026 | 17/6/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Alta (8.8) | 0.66% | — | ALL IN ONE Video GalleryAI | 16/1/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validation detecting VTT files, allowing double extension files to bypass sanitization while being accepted as a valid VTT file. This makes it… | |
| Aplazada | Media (5.3) | 0.29% | — | RE GalleryAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Re Gallery: from n/a through 1.18.9. | |
| Aplazada | Alta (7.1) | 0.26% | — | Lambertgroup Famous - Responsive Image AND Video Grid GalleryAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Famous - Responsive Image And Video Grid Gallery WordPress Plugin famous_grid_image_and_video_gallery allows Reflected XSS.This issue affects Famous - Responsive Image And Video Grid Gallery WordPress… | |
| Aplazada | Media (6.4) | 0.22% | — | MY Album GalleryAI | 7/1/2026 | 17/6/2026 | The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode attribute in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.4) | 0.32% | — | STM GalleryAI | 7/1/2026 | 17/6/2026 | The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in all versions up to, and including, 0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.38% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 7/10/2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37. | |
| Aplazada | Alta (7.1) | 0.22% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25. | |
| Aplazada | Media (6.4) | 0.26% | — | MY Album GalleryAI | 7/1/2026 | 7/10/2026 | The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image titles in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on the 'attachment->title' attribute. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.22% | — | Gt3themes Photo GalleryAI | 6/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Reflected XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.26. | |
| Aplazada | Alta (8.8) | 0.35% | — | Digitalzoomstudio DZS Video GalleryAI | 6/1/2026 | 7/10/2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25. | |
| Aplazada | Alta (7.1) | 0.18% | — | Terry Zielke Zielke Design Project GalleryAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Zielke Zielke Design Project Gallery zielke-design-project-gallery allows Reflected XSS.This issue affects Zielke Design Project Gallery: from n/a through <= 2.5.0. | |
| Aplazada | Media (4.3) | 0.12% | — | Serhii Pasyuk Gmedia Photo GalleryAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery grand-media allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through <= 1.25.0. | |
| Aplazada | Media (4.3) | 0.18% | — | Wpdiscover Accordion Slider GalleryAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdiscover Accordion Slider Gallery accordion-slider-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through <= 2.7. | |
| Aplazada | Media (5.4) | 0.25% | — | Huge-it Portfolio GalleryAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in totalsoft Portfolio Gallery gallery-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery: from n/a through <= 1.4.8. | |
| Aplazada | Media (6.4) | 0.23% | — | Image Photo Gallery Final Tiles GridAI | 21/12/2025 | 17/6/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… |