Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.25%—Gmedia Photo GalleryAI6/10/20266/10/2026
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
AplazadaMedia (6.1)0.23%—10web Photo GalleryAI3/10/20266/10/2026
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaAlta (8.8)0.29%—10web Photo GalleryAI30/9/202630/9/2026
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
AplazadaMedia (5.4)0.10%—Supsystic Photo GalleryAI30/9/202630/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
AplazadaMedia (4.2)0.19%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging…
AplazadaBaja (2.7)0.30%—Photo Gallery Sliders Proofing ANDAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including…
AplazadaAlta (7.2)0.50%—Photo Gallery Sliders Proofing WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator…
AplazadaMedia (6.5)0.55%—10web Photo GalleryAI18/9/202618/9/2026
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (6.4)0.26%—10web Photo GalleryAI17/9/202617/9/2026
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.20%—10web Photo GalleryAI2/9/20263/9/2026
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in…
AplazadaMedia (4.9)0.59%—AYS Photo GalleryAI1/9/20262/9/2026
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaBaja (2)0.35%—Coppermine-gallery Coppermine Photo GalleryAI30/8/202631/8/2026
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be…
AplazadaBaja (2)0.35%—Coppermine Photo GalleryAI30/8/20261/9/2026
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The attack can be initiated remotely. The…
AplazadaMedia (6.4)0.33%—Image Photo Gallery Final Tiles GridAI22/8/202624/8/2026
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.22%—Photo GalleryAI23/7/202623/7/2026
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
AplazadaMedia (5.9)0.24%—Supsystic Photo GalleryAI23/7/202623/7/2026
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
AplazadaMedia (6.5)0.33%—Envira Photo GalleryAI16/6/202617/6/2026
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
AplazadaAlta (8.7)0.64%—MAC Photo GalleryAI9/6/202621/7/2026
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin…
AplazadaAlta (8.8)0.26%—Pica Photo GalleryAI9/6/202621/7/2026
WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database…
AplazadaMedia (6.5)0.55%—10web Photo GalleryAI6/6/202623/7/2026
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaAlta (7.6)0.38%—Photo Gallery BY 10webAI4/6/202622/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
AplazadaAlta (8.8)0.34%—Joomla JE Photo GalleryAI1/6/202622/7/2026
Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery…
AplazadaMedia (6.5)0.55%—10web Photo GalleryAI28/5/202617/6/2026
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…