Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.27%—Wpchill Modula Image GalleryAI25/9/202625/9/2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above,…
AplazadaAlta (7.5)0.39%—Wpchill Modula Image GalleryAI25/9/202625/9/2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via…
Pendiente de análisisCrítica (9.1)0.23%—Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI25/8/202628/8/2026
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
AplazadaMedia (6.5)0.22%—Wpchill Modula Image GalleryAI23/7/202623/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
AplazadaMedia (6.5)0.22%—Wpchill Modula Image GalleryAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
AplazadaAlta (7.2)0.54%—Modula Image GalleryAI15/6/202617/6/2026
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
AplazadaMedia (6.4)0.32%—Easy Image GalleryAI25/3/202617/6/2026
The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up to, and including, 1.5.3. This is due to insufficient input sanitization and output escaping on user-supplied gallery shortcode values. This makes it possible for…
AnalizadaMedia (5.5)0.92%—Remyandrade Modern Image Gallery APP8/3/202617/6/2026
A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2.1)0.48%—Remyandrade Modern Image Gallery APP24/2/202617/6/2026
A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaAlta (8.8)0.36%—WP Life Image Gallery Lightbox Gallery Responsive Photo Gallery Masonry GalleryAI20/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-gallery allows Object Injection.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through <= 1.6.0.
AplazadaMedia (6.4)0.32%—Essentialplugin Album AND Image Gallery Plus LightboxAI19/2/202617/6/2026
The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `aigpl-gallery-album` shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (4.3)0.19%—Wpchill Modula Image GalleryAI14/2/202617/6/2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API. This makes it…
AplazadaMedia (4.3)0.23%—Wpchill Modula Image GalleryAI3/2/202617/6/2026
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image Gallery: from n/a through <= 2.13.6.
AnalizadaCrítica (9.8)0.92%—Remyandrade Modern Image Gallery APP23/1/202617/6/2026
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an…
AplazadaMedia (5.9)0.20%—Wpchill Modula Image GalleryAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4.
AplazadaMedia (4.3)0.24%—Modula Image GalleryAI15/12/202517/6/2026
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `add_images_to_gallery_callback()` function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with Author-level…
AplazadaMedia (6.5)0.42%—Image GalleryAI12/12/202530/9/2026
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. This is due to the modula_list_folders AJAX endpoint that lacks proper path validation and base directory restrictions. While the endpoint verifies user capabilities…
AnalizadaMedia (6.6)0.75%—Wpchill Modula Image Gallery3/12/202517/6/2026
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files with race condition…
AnalizadaAlta (7.2)1.0%—Wpchill Modula Image Gallery3/12/202517/6/2026
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the…
AplazadaMedia (4.3)0.24%—Image Gallery Photo Grid Video GalleryAI15/11/202517/6/2026
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above,…
AplazadaAlta (7.1)0.27%—Bplugins Image Gallery BlockAI6/11/202517/6/2026
Missing Authorization vulnerability in bPlugins Image Gallery block – Create and display photo gallery/photo album. 3d-image-gallery allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Image Gallery block – Create and display photo gallery/photo album.: from n/a through <= 1.0.7.
AplazadaMedia (5.3)0.75%—Iberezansky 3D Flipbook PDF Flipbook Viewer Flipbook Image GalleryAI22/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine allows Retrieve Embedded Sensitive Data.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through…
AplazadaMedia (6.1)0.26%—Image GalleryAI2/8/202517/6/2026
The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user…
AplazadaMedia (6.5)0.26%—Nayon46 Awesome WP Image GalleryAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Awesome Wp Image Gallery awesome-wp-image-gallery allows Stored XSS.This issue affects Awesome Wp Image Gallery: from n/a through <= 1.0.
AplazadaAlta (7.1)0.29%—Uxgallery Photo Image GalleryAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxgallery WordPress Photo Gallery – Image Gallery photo-image-gallery allows Reflected XSS.This issue affects WordPress Photo Gallery – Image Gallery: from n/a through <= 2.0.4.