Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5) | 0.27% | — | Plugins360 All-in-one Video GalleryAI | 10/8/2026 | 26/8/2026 | All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester. | |
| Aplazada | Media (6.4) | 0.42% | — | ALL IN ONE Video GalleryAI | 10/7/2026 | 10/7/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from… | |
| Aplazada | Media (4.4) | 0.34% | — | Product Video Gallery FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop… | |
| Aplazada | Media (6.1) | 0.24% | — | ALL IN ONE Video GalleryAI | 4/3/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vi' parameter in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.18% | — | ALL IN ONE Video GalleryAI | 24/1/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Media (4.3) | 0.15% | — | WP Youtube Video GalleryAI | 24/1/2026 | 17/6/2026 | The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce verification on the wpYTVideoGallerySettingSave() function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged… | |
| Aplazada | Media (6.5) | 0.41% | — | ALL IN ONE Video Gallery All-in-one-video-galleryAI | 23/1/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_callback_delete_bunny_stream_video` functions in all versions up to, and including,… | |
| Aplazada | Alta (8.5) | 0.43% | — | DZS Video GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allows SQL Injection.This issue affects DZS Video Gallery: from n/a through <= 12.39. | |
| Aplazada | Alta (8.8) | 0.66% | — | ALL IN ONE Video GalleryAI | 16/1/2026 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validation detecting VTT files, allowing double extension files to bypass sanitization while being accepted as a valid VTT file. This makes it… | |
| Aplazada | Crítica (9.8) | 0.38% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37. | |
| Aplazada | Alta (7.1) | 0.22% | — | Digitalzoomstudio DZS Video GalleryAI | 7/1/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25. | |
| Aplazada | Alta (8.8) | 0.35% | — | Digitalzoomstudio DZS Video GalleryAI | 6/1/2026 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25. | |
| Aplazada | Alta (8.8) | 0.52% | — | ALL IN ONE Video GalleryAI | 6/12/2025 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_directory() function in versions 4.5.4 to 4.5.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the… | |
| Aplazada | Media (4.3) | 0.24% | — | Image Gallery Photo Grid Video GalleryAI | 15/11/2025 | 17/6/2026 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Aplazada | Media (6.5) | 0.20% | — | Huzzaz Video GalleryAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deshine Video Gallery by Huzzaz huzzaz-video-gallery allows Stored XSS.This issue affects Video Gallery by Huzzaz: from n/a through <= 10.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Origincode Video Gallery - Vimeo AND Youtube GalleryAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in origincode Video Gallery – Vimeo and YouTube Gallery smart-grid-gallery allows Stored XSS.This issue affects Video Gallery – Vimeo and YouTube Gallery: from n/a through <= 1.1.7. | |
| Aplazada | Media (6.5) | 0.19% | — | Bplugins Video Gallery BlockAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block video-gallery-block allows Stored XSS.This issue affects Video Gallery Block: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Riosisgroup RIO Video GalleryAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery rio-video-gallery allows Stored XSS.This issue affects Rio Video Gallery: from n/a through <= 2.3.6. | |
| Aplazada | Alta (7.1) | 0.24% | — | Extendyourweb Ultimate Video GalleryAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendyourweb ULTIMATE VIDEO GALLERY ultimate-gallery allows Reflected XSS.This issue affects ULTIMATE VIDEO GALLERY: from n/a through <= 1.4. | |
| Aplazada | Alta (7.5) | 0.84% | — | Total-soft Video Gallery Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6. | |
| Analizada | Media (4.8) | 0.31% | — | Total-soft Video Gallery | 6/12/2024 | 17/6/2026 | The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Analizada | Media (4.9) | 0.53% | — | Total-soft Video Gallery | 6/12/2024 | 17/6/2026 | The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Modificada | Crítica (9.8) | 1.1% | — | LIS Video Gallery | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1. | |
| Analizada | Media (5.3) | 0.40% | — | Martinvalchev Video Gallery FOR Woocommerce | 6/11/2024 | 17/6/2026 | The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnails in the… | |
| Modificada | Media (5.4) | 0.33% | — | Plugins360 All-in-one Video Gallery | 24/7/2024 | 17/6/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |