Known Vulnerabilities for Gallery by Gallery Project
Listed below are 10 of the newest known vulnerabilities associated with "Gallery" by "Gallery Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78238 json | SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the use... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-76611 json | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-74007 json | Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-73184 json | Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-67204 json | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-66916 json | Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An una... | Not Provided | 2026-08-22 | 2026-08-26 |
| CVE-2026-66448 json | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-66434 json | Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-66396 json | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover im... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-65713 json | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate un... | Not Provided | 2026-07-23 | 2026-07-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gallery Project | Gallery | 1.4 | |||
| Application | Gallery Project | Gallery | 1.3 | |||
| Application | Gallery Project | Gallery | 1.2 | |||
| Application | Gallery Project | Gallery | 1.1 | |||
| Application | Gallery Project | Gallery | 1.0 |