Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.29% | — | Image Photo Gallery Final Tiles GridAI | 19/12/2025 | 17/6/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to perform actions on gallery management functions. This makes it possible for authenticated… | |
| Analizada | Media (5.1) | 0.24% | — | Tinywebgallery | 18/12/2025 | 17/6/2026 | TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages. | |
| Aplazada | Alta (8.8) | 0.75% | — | Photogallery Nextgen GalleryAI | 18/12/2025 | 17/6/2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.59.12 via the 'template' shortcode parameter. This is due to insufficient path validation that allows absolute paths to be provided. This makes it… | |
| Analizada | Crítica (9.3) | 1.1% | — | Tinywebgallery | 17/12/2025 | 17/6/2026 | TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL. | |
| Analizada | Alta (8.7) | 0.85% | — | Coppermine-gallery Coppermine Photo Gallery | 15/12/2025 | 17/6/2026 | Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script. | |
| Aplazada | Media (4.3) | 0.24% | — | Modula Image GalleryAI | 15/12/2025 | 17/6/2026 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `add_images_to_gallery_callback()` function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Baja (1.9) | 0.20% | — | Atlaszz AI Photo Team GalleryAI | 15/12/2025 | 17/6/2026 | A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part of the component gallery.photogallery.pictures.vault.album. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been made available to the public and… | |
| Aplazada | Media (4.3) | 0.22% | — | Gallery Blocks With LightboxAI | 13/12/2025 | 17/6/2026 | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to unauthorized modification of plugin settings in all versions up to, and including, 3.3.0. This is due to the plugin using the `edit_posts` capability check… | |
| Aplazada | Media (6.5) | 0.42% | — | Image GalleryAI | 12/12/2025 | 30/9/2026 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation and base directory restrictions. While the endpoint verifies user capabilities… | |
| Aplazada | Media (4.3) | 0.22% | — | SimplegalleryAI | 12/12/2025 | 30/9/2026 | The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.20% | — | Jegtheme Jnews GalleryAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews Gallery jnews-gallery allows Stored XSS.This issue affects JNews Gallery: from n/a through < 12.0.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Simplygallery Simply GalleryAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Stored XSS.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.1. | |
| Aplazada | Alta (8.8) | 0.52% | — | ALL IN ONE Video GalleryAI | 6/12/2025 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_directory() function in versions 4.5.4 to 4.5.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the… | |
| Aplazada | Media (6.4) | 0.23% | — | Social Feed Gallery PortfolioAI | 6/12/2025 | 17/6/2026 | The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [igp-wp] shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.14% | — | Dream GalleryAI | 5/12/2025 | 17/6/2026 | The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'dreampluginsmain' AJAX action. This makes it possible for unauthenticated attackers to update the plugin's settings and inject… | |
| Aplazada | Alta (8.8) | 0.76% | 💥 PoC | PostgalleryAI | 4/12/2025 | 17/6/2026 | The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload… | |
| Analizada | Media (6.6) | 0.75% | — | Wpchill Modula Image Gallery | 3/12/2025 | 17/6/2026 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files with race condition… | |
| Analizada | Alta (7.2) | 1.0% | — | Wpchill Modula Image Gallery | 3/12/2025 | 17/6/2026 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the… | |
| Aplazada | Media (4.3) | 0.16% | — | AYS Photo GalleryAI | 2/12/2025 | 17/6/2026 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for unauthenticated attackers to perform bulk… | |
| Aplazada | Alta (8.1) | 0.63% | — | WP Audio GalleryAI | 21/11/2025 | 17/6/2026 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter before… | |
| Aplazada | Media (6.4) | 0.24% | — | LightgalleryAI | 20/11/2025 | 17/6/2026 | Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.4) | 0.24% | — | Responsive Lightbox GalleryAI | 19/11/2025 | 17/6/2026 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it… | |
| Aplazada | Media (5.3) | 0.32% | — | Contest-gallery Contest GalleryAI | 15/11/2025 | 17/6/2026 | The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing capability checks or nonce… | |
| Aplazada | Media (4.3) | 0.24% | — | Image Gallery Photo Grid Video GalleryAI | 15/11/2025 | 17/6/2026 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Aplazada | Media (4.3) | 0.32% | — | Enviragallery Envira GalleryAI | 13/11/2025 | 17/6/2026 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Author-level access and above, to… |