Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.19%—Filterable Portfolio GalleryAI10/5/202625/7/2026
Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed,…
AplazadaMedia (5.4)0.25%—Huge-it Portfolio GalleryAI31/12/202517/6/2026
Missing Authorization vulnerability in totalsoft Portfolio Gallery gallery-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery: from n/a through <= 1.4.8.
AplazadaMedia (6.4)0.32%—Portfolio Filterable Masonry Portfolio Gallery FOR ProfessionalsAI17/12/202417/6/2026
The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This…
AplazadaAlta (7.5)0.83%—Total-soft Portfolio Gallery Responsive Image GalleryAI13/12/202417/6/2026
Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6.
AplazadaMedia (6.4)0.34%—Huge-it Portfolio GalleryAI27/6/202417/6/2026
The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PFG' shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.5)0.91%—Photo Gallery Responsive Photo Gallery Image Gallery Portfolio Gallery Logo Gallery AND Team GalleryAI2/5/202417/6/2026
The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.2 via deserialization via shortcode of untrusted input from the 'awl_lg_settings_' attribute. This makes it…
AplazadaMedia (6.5)0.35%—Portfolio Gallery Image Gallery PluginAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portfolio Gallery – Image Gallery Plugin allows Stored XSS.This issue affects Portfolio Gallery – Image Gallery Plugin: from n/a through 1.5.6.
ModificadaMedia (6.1)0.46%—Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio31/7/202317/6/2026
The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.8)0.71%—Huge-it Portfolio Gallery28/5/202317/6/2026
A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 is able to address this issue. The identifier of the patch is…
ModificadaMedia (4.8)0.37%—Simple Portfolio Gallery Project Simple Portfolio Gallery4/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions.
ModificadaMedia (5.4)0.60%—Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio11/4/202217/6/2026
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform…
ModificadaMedia (6.5)0.55%—Phoeniixx Filter Portfolio Gallery13/12/202117/6/2026
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.
ModificadaAlta (7.2)2.1%—Huge-it Portfolio Gallery Manager21/10/201617/6/2026
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
ModificadaAlta (7.2)2.9%—Huge-it Portfolio Gallery Manager21/10/201617/6/2026
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
ModificadaCrítica (9.8)2.5%—Huge-it Portfolio Gallery6/10/201617/6/2026
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6