Vulnerabilities in WPChill
66 resultsVexday analysis
WPChill apresenta um perfil de risco moderado com 14 vulnerabilidades catalogadas, predominantemente problemas de XSS (CWE-79). Nenhuma vulnerabilidade está sob exploração ativa documentada, e apenas 1 é crítica, indicando exposição controlada. O portfólio não recebeu atualizações de vulnerabilidades nos últimos 90 dias, sugerindo risco estável mas sem remediação recente.
CVE-2024-9416MEDIUMModula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript LibraryEPSS 0.2%CVE-2025-15466MEDIUMImage Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery ManagementEPSS 0.2%CVE-2026-4401MEDIUMDownload Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and DisablingEPSS 0.2%CVE-2026-1254MEDIUMModula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page EditingEPSS 0.2%CVE-2026-92713HIGHModula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' ParameterEPSS —CVE-2026-89406HIGHModula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' ParametersEPSS —