Known Vulnerabilities for Envira Gallery by Unknown
Listed below are 4 of the newest known vulnerabilities associated with "Envira Gallery" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104653 json | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration va... | Not Provided | 2026-10-07 | 2026-10-07 |
| CVE-2026-104652 json | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting i... | Not Provided | 2026-10-07 | 2026-10-07 |
| CVE-2026-104079 json | Envira Gallery Lite before 1.16.2 contains a missing authorization vulnerability in its gallery conversion REST endpoint that... | Not Provided | 2026-10-09 | 2026-10-09 |
| CVE-2026-3423 json | The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configurat... | Not Provided | 2026-08-28 | 2026-08-28 |