Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39781 | 2 Dan Rossiter, Wordpress-extensions | 2 Document Gallery, Document Gallery | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | ||||
| CVE-2026-12982 | 2 Dan Rossiter, Wordpress | 2 Document Gallery, Wordpress | 2026-07-28 | 6.1 Medium |
| The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users. | ||||
| CVE-2026-57695 | 2 Dan Rossiter, Wordpress | 2 Document Gallery, Wordpress | 2026-07-13 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0. | ||||
Page 1 of 1.