Inpost gallery
This hub aggregates every CVE we track for Inpost gallery, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
2
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM3CRITICAL2HIGH1
Monthly trend
0
0
1
0
0
0
0
1
0
0
0
0
1
0
0
0
0
0
0
0
0
1
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Inpost gallery.
- CVE-2026-39574WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability9.3
- CVE-2025-57889WordPress InPost Gallery Plugin <= 2.1.4.5 - Local File Inclusion Vulnerability7.5
- CVE-2025-26903WordPress InPost Gallery plugin <= 2.1.4.3 - Cross Site Request Forgery (CSRF) vulnerability4.3
- CVE-2024-11002InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template6.3
- CVE-2023-28666The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which ...5.4
- CVE-2022-4063InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE9.8
Product normalization is registry-driven with AI assist and human review. How it works