VendorsWPChillmodula_image_galleryall versions
Vulnerabilities

WPChill Modula Image Gallery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-12853
Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload
Published 2025-01-08 · Analyzed
8.8EPSS 0.009
CVE-2025-13646
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition
Published 2025-12-03 · Analyzed
7.5EPSS 0.008
CVE-2025-13645
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
Published 2025-12-03 · Analyzed
7.2EPSS 0.010
CVE-2024-9416
Modula Image Gallery <= 2.10.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox 5 JavaScript Library
Published 2025-04-03 · Analyzed
6.4EPSS 0.002
CVE-2020-9003
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
Published 2020-02-20 · Modified
5.4EPSS 0.010