Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.19% | — | Filterable Portfolio GalleryAI | 10/5/2026 | 25/7/2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed,… | |
| Aplazada | Media (5.4) | 0.25% | — | Huge-it Portfolio GalleryAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in totalsoft Portfolio Gallery gallery-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery: from n/a through <= 1.4.8. | |
| Aplazada | Media (6.4) | 0.32% | — | Portfolio Filterable Masonry Portfolio Gallery FOR ProfessionalsAI | 17/12/2024 | 17/6/2026 | The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Alta (7.5) | 0.83% | — | Total-soft Portfolio Gallery Responsive Image GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6. | |
| Aplazada | Media (6.4) | 0.34% | — | Huge-it Portfolio GalleryAI | 27/6/2024 | 17/6/2026 | The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PFG' shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.91% | — | Photo Gallery Responsive Photo Gallery Image Gallery Portfolio Gallery Logo Gallery AND Team GalleryAI | 2/5/2024 | 17/6/2026 | The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.2 via deserialization via shortcode of untrusted input from the 'awl_lg_settings_' attribute. This makes it… | |
| Aplazada | Media (6.5) | 0.35% | — | Portfolio Gallery Image Gallery PluginAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portfolio Gallery – Image Gallery Plugin allows Stored XSS.This issue affects Portfolio Gallery – Image Gallery Plugin: from n/a through 1.5.6. | |
| Modificada | Media (6.1) | 0.46% | — | Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio | 31/7/2023 | 17/6/2026 | The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 0.71% | — | Huge-it Portfolio Gallery | 28/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 is able to address this issue. The identifier of the patch is… | |
| Modificada | Media (4.8) | 0.37% | — | Simple Portfolio Gallery Project Simple Portfolio Gallery | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions. | |
| Modificada | Media (5.4) | 0.60% | — | Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio | 11/4/2022 | 17/6/2026 | The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform… | |
| Modificada | Media (6.5) | 0.55% | — | Phoeniixx Filter Portfolio Gallery | 13/12/2021 | 17/6/2026 | The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery. | |
| Modificada | Alta (7.2) | 2.1% | — | Huge-it Portfolio Gallery Manager | 21/10/2016 | 17/6/2026 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | |
| Modificada | Alta (7.2) | 2.9% | — | Huge-it Portfolio Gallery Manager | 21/10/2016 | 17/6/2026 | Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | |
| Modificada | Crítica (9.8) | 2.5% | — | Huge-it Portfolio Gallery | 6/10/2016 | 17/6/2026 | Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 |