plugin

Gallery By Supsystic Vulnerabilities

11 known security issues reported for the Gallery By Supsystic WordPress plugin. Most recent disclosed Jul 22, 2026.

1 high 3 medium

Running Gallery By Supsystic on your site? Check whether your installed version is affected.

Scan your site free

Photo Gallery – Responsive Image Galleries by Supsystic <= 1.16.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Photo Gallery – Responsive Image Galleries by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above...

CVSS:
4.4
Affected:
up to 1.16.3
Fixed in:
1.17.0
Disclosed:
Jul 22, 2026

CVE-2026-24628 on NVD →

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.15.17

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Photo Gallery by Supsystic allows Stored XSS.This issue affects Photo Gallery by Supsystic: from n/a through 1.15.16.

Affected:
up to 1.15.17
Fixed in:
1.15.17
Disclosed:
Mar 27, 2024

CVE-2024-29921 on NVD →

Photo Gallery by Supsystic <= 1.15.16 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
5.5
Affected:
up to 1.15.16
Fixed in:
1.15.17
Disclosed:
Mar 25, 2024

CVE-2024-29921 on NVD →

Photo Gallery by Supsystic <= 1.15.5 - Cross-Site Request Forgery to Plugin Settings Change

medium

Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.

CVSS:
5.4
Affected:
up to 1.15.5
Fixed in:
1.15.6
Disclosed:
Jun 15, 2022

CVE-2021-36891 on NVD →

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.15.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.

Affected:
up to 1.15.6
Fixed in:
1.15.6
Disclosed:
Jun 15, 2022

CVE-2021-36891 on NVD →

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6

unknown

[en] The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.

Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Aug 22, 2019

CVE-2016-10918 on NVD →

Photo Gallery by Supsystic <= 1.8.8 - Cross-Site Request Forgery

high

The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.5. This is due to missing or incorrect nonce validation on the 'updateAttachment' action. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forge...

CVSS:
8.8
Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Aug 15, 2016

CVE-2016-10918 on NVD →

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6

unknown

Because of this vulnerability, the attackers can add images to a gallery. Update the plugin.

Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Aug 15, 2016

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6

unknown

Because of this vulnerability, the attackers can steal users' session tokens or perform arbitrary actions on their behalf. Update the plugin.

Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Aug 14, 2016

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.2.6

unknown

WordPress Photo Gallery by Supsystic plugin unrestricted file upload vulnerability allows an access to upload functionality via "UploadHandler.php". Update to version 1.2.6.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Nov 11, 2014

Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6

unknown

The plugin does not have CSRF check in place and it lacking sanitisation as well as escaping via in AJAX action to update attachment, which could lead to Stored XSS via CSRF

Affected:
up to 1.8.6
Fixed in:
1.8.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database