Vulnerabilities
Summary — last 7 days
New vulnerabilities2,687▼ 562 vs. last week
Critical / high1,259▼ 239 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)265▼ 239 vs. last week
220 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.3) | 0.27% | — | Wpchill Image Photo Gallery Final Tiles GridAI | 5/20/2026 | 7/24/2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11. | |
| Deferred | Low (2.7) | 0.28% | — | WP Chill Image Photo Gallery Final Tiles Grid Gallery LiteAI | 4/8/2026 | 7/24/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11. | |
| Deferred | Medium (4.3) | 0.14% | — | 10web Photo GalleryAI | 3/13/2026 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request Forgery.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37. | |
| Deferred | High (8.7) | 0.67% | — | Coppermine Photo GalleryAI | 3/11/2026 | 6/17/2026 | Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28. | |
| Deferred | High (8.8) | 0.36% | — | WP Life Image Gallery Lightbox Gallery Responsive Photo Gallery Masonry GalleryAI | 2/20/2026 | 6/17/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-gallery allows Object Injection.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through <= 1.6.0. | |
| Deferred | Medium (5.9) | 0.25% | — | 10web Photo GalleryAI | 2/19/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.38. | |
| Deferred | Medium (4.3) | 0.25% | — | Wpchill Image Photo Gallery Final Tiles GridAI | 2/19/2026 | 6/17/2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.10. | |
| Deferred | Medium (4.3) | 0.28% | — | Navz ACF Photo Gallery FieldAI | 2/19/2026 | 6/17/2026 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "acf_photo_gallery_edit_save" function in all versions up to, and including, 3.0. This makes it possible for authenticated attackers, with subscriber level access and above, to… | |
| Deferred | High (7.1) | 0.30% | — | Adamlabs Wordpress Photo GalleryAI | 1/22/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0. | |
| Deferred | Medium (5.3) | 0.25% | — | 10web Photo GalleryAI | 1/22/2026 | 6/17/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Deferred | Medium (5.4) | 0.22% | — | Image Photo Gallery Final Tiles GridAI | 1/20/2026 | 6/17/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Deferred | High (7.1) | 0.22% | — | Gt3themes Photo GalleryAI | 1/6/2026 | 10/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Reflected XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.26. | |
| Deferred | Medium (4.3) | 0.12% | — | Serhii Pasyuk Gmedia Photo GalleryAI | 12/31/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery grand-media allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through <= 1.25.0. | |
| Deferred | Medium (6.4) | 0.23% | — | Image Photo Gallery Final Tiles GridAI | 12/21/2025 | 6/17/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Deferred | Medium (5.4) | 0.29% | — | Image Photo Gallery Final Tiles GridAI | 12/19/2025 | 6/17/2026 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to perform actions on gallery management functions. This makes it possible for authenticated… | |
| Analyzed | High (8.7) | 0.85% | — | Coppermine-gallery Coppermine Photo Gallery | 12/15/2025 | 6/17/2026 | Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script. | |
| Deferred | Medium (4.3) | 0.16% | — | AYS Photo GalleryAI | 12/2/2025 | 6/17/2026 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for unauthenticated attackers to perform bulk… | |
| Deferred | Medium (4.3) | 0.20% | — | Enviragallery Envira Photo GalleryAI | 11/8/2025 | 6/17/2026 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/envira-convert/v1/bulk-convert' REST API endpoint in all versions up to, and including, 1.11.0. This makes it possible for authenticated attackers,… | |
| Deferred | Medium (6.5) | 0.28% | — | AYS Gallery-photo-galleryAI | 9/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays gallery-photo-gallery allows DOM-Based XSS.This issue affects Photo Gallery by Ays: from n/a through <= 6.3.8. | |
| Analyzed | Medium (5.5) | 0.55% | — | Fabian Simple Photo Gallery | 6/29/2025 | 6/17/2026 | A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file /upload-photo.php. The manipulation of the argument file_img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Deferred | High (7.5) | 0.72% | — | Serhii Pasyuk Gmedia Photo GalleryAI | 6/27/2025 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Serhii Pasyuk Gmedia Photo Gallery grand-media allows PHP Local File Inclusion.This issue affects Gmedia Photo Gallery: from n/a through <= 1.23.0. | |
| Analyzed | Medium (4.8) | 0.35% | — | 10web Photo Gallery | 5/15/2025 | 6/17/2026 | The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Deferred | Medium (6.5) | 0.21% | — | Gt3themes Photo GalleryAI | 5/7/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Stored XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.25. | |
| Deferred | Medium (6.1) | 0.26% | — | 10web Photo GalleryAI | 4/12/2025 | 6/17/2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘image_id’ parameter in all versions up to, and including, 1.8.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Deferred | High (7.6) | 0.58% | — | Suiteplugins Video AND Photo Gallery FOR Ultimate MemberAI | 4/4/2025 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows SQL Injection.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.3. |