VYPR

Document Gallery

by WordPress

CVEs (2)

  • CVE-2026-12982Jul 27, 2026
    risk 0.00cvss epss 0.00

    The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against…

  • CVE-2026-57695Jul 13, 2026
    risk 0.00cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.