Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Andy Urlep

#18386of 57,675
16.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-109519
6.8
2026-10-10
WordPress · Gallery Photoblocks · CVE-2026-107323
**Name of the Vulnerable Software and Affected Versions** Gallery PhotoBlocks versions prior to 1.3.6 **Description** Insufficient sanitization and escaping of a gallery setting before it is output into an HTML attribute allows users with Contributor-level access and above to perform a Stored Cross-Site Scripting (XSS) attack. This enables the storage of malicious JavaScript that executes in the browser of any user viewing a page containing the gallery, including those with administrator privileges. **Recommendations** Update Gallery PhotoBlocks to version 1.3.6 or later.
PT-2026-103881
9.3
2026-10-01
WordPress · Wordpress File Upload · CVE-2026-62071
**Name of the Vulnerable Software and Affected Versions** WordPress File Upload versions prior to 5.1.11 **Description** An unauthenticated SQL Injection exists in the software. SQL Injection is a type of vulnerability that allows an attacker to interfere with the queries that an application makes to its database. **Recommendations** Update to a version newer than 5.1.10.