Known Vulnerabilities for Gallery From Files by Gallery From Files Project

Listed below are 1 of the newest known vulnerabilities associated with "Gallery From Files" by "Gallery From Files Project".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-48945 json The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames... Not Provided 2026-06-25 2026-06-28
CVE-2026-42028 json novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery... Not Provided 2026-05-08 2026-05-08
CVE-2026-11989 json The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnera... Not Provided 2026-06-19 2026-06-23
CVE-2026-6566 json The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Obj... Not Provided 2026-05-20 2026-05-20
CVE-2024-24887 json Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload ... Not Provided 2024-02-12 2026-04-28
CVE-2023-47548 json URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Downl... Not Provided 2023-12-07 2026-04-28
CVE-2023-26961 json Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers ... Not Provided 2023-08-08 2026-07-09
CVE-2021-24349 json This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenam... 6.1 - MEDIUM 2021-06-14 2022-11-09
CVE-2017-20250 json Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary fil... 6.1 - MEDIUM 2026-06-09 2026-06-09
CVE-2017-20248 json Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary... 6.1 - MEDIUM 2026-06-09 2026-06-09

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report