Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | Videowhisper Picture GalleryAI | 23/7/2026 | 23/7/2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress Picture GalleryAI | 10/5/2026 | 25/7/2026 | WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options that are stored in the database and… | |
| Aplazada | Alta (7.1) | 0.37% | — | Videowhisper Picture GalleryAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Picture Gallery picture-gallery allows Reflected XSS.This issue affects Picture Gallery: from n/a through <= 1.6.3. | |
| Analizada | Media (5.4) | 0.31% | — | Videowhisper Picture Gallery | 22/1/2025 | 17/6/2026 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up to, and including, 1.5.19 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (6.4) | 0.41% | — | Picture Gallery Frontend Image Uploads Ajax Photo ListAI | 18/1/2025 | 17/6/2026 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (5.4) | 0.25% | — | Videowhisper Picture Gallery | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from n/a through 1.5.11. | |
| Modificada | Alta (7.5) | 1.7% | — | JMK WEB Scripts JMK Picture Gallery | 1/5/2006 | 16/6/2026 | JMK's Picture Gallery allows remote attackers to bypass authentication via a direct request to admin_gallery.php3, possibly related to the add action. |