Envira gallery – image photo gallery, albums, video gallery, slideshows & more
This hub aggregates every CVE we track for Envira gallery – image photo gallery, albums, video gallery, slideshows & more, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM6
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
2
0
0
0
1
0
1
0
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Envira gallery – image photo gallery, albums, video gallery, slideshows & more.
- CVE-2026-5361Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter6.4
- CVE-2026-1236Envira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API6.4
- CVE-2025-12377Gallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions4.3
- CVE-2025-11448Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion4.3
- CVE-2024-5020Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library6.4
- CVE-2023-6742Envira Gallery Lite <= 1.8.7.2 - Missing Authorization to Gallery Modification via envira_gallery_insert_images4.3
Product normalization is registry-driven with AI assist and human review. How it works