CVE-2026-105876
- EPSS 0.25%
- Veröffentlicht 07.10.2026 09:16:26
- Zuletzt bearbeitet 07.10.2026 13:24:53
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11.
CVE-2026-89406
- EPSS 0.39%
- Veröffentlicht 25.09.2026 07:40:28
- Zuletzt bearbeitet 25.09.2026 14:17:21
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked...
CVE-2026-92713
- EPSS 0.27%
- Veröffentlicht 25.09.2026 07:40:25
- Zuletzt bearbeitet 25.09.2026 14:17:22
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possi...
CVE-2026-65475
- EPSS 0.13%
- Veröffentlicht 23.07.2026 11:53:14
- Zuletzt bearbeitet 23.07.2026 16:17:50
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
CVE-2026-42688
- EPSS 0.24%
- Veröffentlicht 15.06.2026 20:18:49
- Zuletzt bearbeitet 15.06.2026 21:24:32
Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
CVE-2026-39481
- EPSS 0.45%
- Veröffentlicht 15.06.2026 20:17:51
- Zuletzt bearbeitet 15.06.2026 21:24:32
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
CVE-2026-1254
- EPSS 0.18%
- Veröffentlicht 14.02.2026 08:26:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specif...
CVE-2026-24939
- EPSS 0.2%
- Veröffentlicht 03.02.2026 14:08:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modula Image Gallery: from n/a through <= 2.13.6.
CVE-2026-23976
- EPSS 0.17%
- Veröffentlicht 22.01.2026 16:52:42
- Zuletzt bearbeitet 28.04.2026 16:16:08
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Stored XSS.This issue affects Modula Image Gallery: from n/a through <= 2.13.4.
CVE-2025-13646
- EPSS 0.74%
- Veröffentlicht 03.12.2025 02:25:30
- Zuletzt bearbeitet 15.12.2025 15:41:08
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-...