PT-2026-64835 · WordPress · Document Gallery

CVE-2026-12982

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Document Gallery versions prior to 5.1.1
Description Insufficient sanitization and escaping of user input in an unauthenticated AJAX action allows for Reflected Cross-Site Scripting (XSS), where malicious scripts are reflected back to unauthenticated users.
Recommendations Update Document Gallery to version 5.1.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12982

Affected Products

Document Gallery