| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-46476 | WordPress Awesome Wp Image Gallery plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability | nayon46 | Awesome Wp Image Gallery | Medium | 6.5 | 2025-04-24 16:08:48 | Deep Dive |
| CVE-2025-27291 | WordPress Photo Gallery – Image Gallery Plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) vulnerability | uxgallery | WordPress Photo Gallery – Image Gallery | High | 7.1 | 2025-04-17 15:48:06 | Deep Dive |
| CVE-2025-32527 | WordPress T&P Gallery Slider plugin <= 1.2 - Stored Cross Site Scripting (XSS) vulnerability | pey22 | T&P Gallery Slider | High | 7.1 | 2025-04-17 15:47:41 | Deep Dive |
| CVE-2025-32649 | WordPress GB Gallery Slideshow Plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | gb-plugins | GB Gallery Slideshow | High | 7.1 | 2025-04-17 15:47:06 | Deep Dive |
| CVE-2025-26903 | WordPress InPost Gallery plugin <= 2.1.4.3 - Cross Site Request Forgery (CSRF) vulnerability | RealMag777 | InPost Gallery | Medium | 4.3 | 2025-04-15 21:53:11 | Deep Dive |
| CVE-2025-22263 | WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability | NotFound | Global Gallery | High | 7.1 | 2025-04-15 21:53:09 | Deep Dive |
| CVE-2025-2269 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter | 10web | Photo Gallery by 10Web – Mobile-Friendly Image Gallery | Medium | 6.1 | 2025-04-11 23:21:55 | Deep Dive |
| CVE-2025-31392 | WordPress Smart Product Gallery Slider plugin <= 1.0.4 - CSRF to Stored XSS vulnerability | Shameem Reza | Smart Product Gallery Slider | High | 7.1 | 2025-04-09 16:10:04 | Deep Dive |
| CVE-2025-32176 | WordPress Gallery Blocks with Lightbox plugin <= 3.2.5 - Stored Cross Site Scripting (XSS) vulnerability | GalleryCreator | SimpLy Gallery | Medium | 6.5 | 2025-04-04 15:58:55 | Deep Dive |
| CVE-2025-32121 | WordPress Video & Photo Gallery for Ultimate Member plugin <= 1.1.3 - SQL Injection vulnerability | SuitePlugins | Video & Photo Gallery for Ultimate Member | High | 7.6 | 2025-04-04 15:58:22 | Deep Dive |
| CVE-2024-9416 | Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library | wpchill | Modula Image Gallery – Photo Grid & Video Gallery | Medium | 6.4 | 2025-04-03 12:22:36 | Deep Dive |
| CVE-2025-31732 | WordPress GB Gallery Slideshow plugin <= 1.3 - Broken Access Control vulnerability | gb-plugins | GB Gallery Slideshow | Medium | 4.3 | 2025-04-01 14:51:02 | Deep Dive |
| CVE-2025-31586 | WordPress Gallery – Photo Albums Plugin plugin <= 1.3.170 - Stored Cross Site Scripting (XSS) vulnerability | GhozyLab | Gallery – Photo Albums Plugin | Medium | 6.5 | 2025-03-31 12:55:26 | Deep Dive |
| CVE-2025-31566 | WordPress Rio Video Gallery plugin <= 2.3.6 - CSRF to Stored XSS vulnerability | riosisgroup | Rio Video Gallery | High | 7.1 | 2025-03-31 12:55:19 | Deep Dive |
| CVE-2025-0613 | Photo Gallery < 1.8.34 - Unauthenticated Stored XSS | Unknown | Photo Gallery by 10Web | 中危 | - | 2025-03-31 06:00:02 | Deep Dive |
| CVE-2025-22566 | WordPress ULTIMATE VIDEO GALLERY Plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability | extendyourweb | ULTIMATE VIDEO GALLERY | High | 7.1 | 2025-03-28 15:12:26 | Deep Dive |
| CVE-2025-22672 | WordPress Video & Photo Gallery for Ultimate Member plugin <= 1.1.2 - Server Side Request Forgery (SSRF) vulnerability | SuitePlugins | Video & Photo Gallery for Ultimate Member | Medium | 4.9 | 2025-03-27 14:11:50 | Deep Dive |
| CVE-2025-28869 | WordPress NextGEN Gallery Voting plugin <= 2.7.6 - Reflected Cross Site Scripting (XSS) vulnerability | shauno | NextGEN Gallery Voting | High | 7.1 | 2025-03-26 14:24:22 | Deep Dive |
| CVE-2025-26581 | WordPress Picture Gallery plugin <= 1.6.3 - CSRF to Stored XSS vulnerability | videowhisper | Picture Gallery | High | 7.1 | 2025-03-26 14:24:21 | Deep Dive |
| CVE-2025-26742 | WordPress Gallery for Social Photo plugin <= 1.0.0.35 - Cross Site Scripting (XSS) vulnerability | GhozyLab | Gallery for Social Photo | Medium | 6.5 | 2025-03-25 14:37:52 | Deep Dive |