Known Vulnerabilities for Gallery by BestWebSoft
Listed below are 3 of the newest known vulnerabilities associated with "Gallery" by "BestWebSoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66448 json | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-66434 json | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-66396 json | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover im... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-65713 json | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate un... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-65519 json | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65475 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image G... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65447 json | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59707 json | LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows ... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-57755 json | Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-57696 json | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bestwebsoft | Gallery | 4.6.7 | |||
| Application | Bestwebsoft | Gallery | 4.6.6 | |||
| Application | Bestwebsoft | Gallery | 4.6.5 | |||
| Application | Bestwebsoft | Gallery | 4.6.4 | |||
| Application | Bestwebsoft | Gallery | 4.6.3 | |||
| Application | Bestwebsoft | Gallery | 4.6.2 | |||
| Application | Bestwebsoft | Gallery | 4.6.1 | |||
| Application | Bestwebsoft | Gallery | 4.6.0 | |||
| Application | Bestwebsoft | Gallery | 4.5.9 | |||
| Application | Bestwebsoft | Gallery | 4.5.8 | |||
| Application | Bestwebsoft | Gallery | 4.5.7 | |||
| Application | Bestwebsoft | Gallery | 4.5.6 | |||
| Application | Bestwebsoft | Gallery | 4.5.5 | |||
| Application | Bestwebsoft | Gallery | 4.5.4 | |||
| Application | Bestwebsoft | Gallery | 4.5.3 | |||
| Application | Bestwebsoft | Gallery | 4.5.2 | |||
| Application | Bestwebsoft | Gallery | 4.5.1 | |||
| Application | Bestwebsoft | Gallery | 4.5.0 | |||
| Application | Bestwebsoft | Gallery | 4.4.9 | |||
| Application | Bestwebsoft | Gallery | 4.4.8 |