Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
1342 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | 10web Photo GalleryAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Books GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | |
| Aplazada | Alta (7.5) | 0.50% | — | Nextgen GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Responsive Slider GalleryAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Supsystic Photo GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated. | |
| Pendiente de análisis | Alta (7) | 0.31% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | |
| Pendiente de análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted. | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | |
| Pendiente de análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name. | |
| Pendiente de análisis | Crítica (9.3) | 0.38% | — | Joomlaboat Youtube GalleryAI | 26/9/2026 | 29/9/2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries. | |
| Aplazada | Alta (8.1) | 0.27% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via… | |
| Aplazada | Baja (2.1) | 0.35% | — | Anirbandutta9 College-notes-galleryAI | 22/9/2026 | 23/9/2026 | A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation of the argument image results in unrestricted upload. It is possible to… | |
| Aplazada | Media (5.5) | 0.41% | — | Anirbandutta9 College-notes-galleryAI | 22/9/2026 | 23/9/2026 | A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a… | |
| Aplazada | Alta (8.6) | 0.37% | — | Ordasoft Joomla GalleryAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled parser into Joomla’s Input object, then reads it back with the ARRAY/ STRING filter types, neither of which sanitises… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Ordasoft Osgallery SearchAIJoomlaAI | 20/9/2026 | 22/9/2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a… | |
| Aplazada | Baja (2.7) | 0.32% | — | Meowapps Meow GalleryAI | 20/9/2026 | 21/9/2026 | The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and… | |
| Aplazada | Media (6.5) | 0.15% | — | Meowapps Meow GalleryAI | 20/9/2026 | 21/9/2026 | The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site. | |
| Aplazada | Media (4.2) | 0.19% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging… | |
| Aplazada | Baja (2.7) | 0.30% | — | Photo Gallery Sliders Proofing ANDAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including… |