CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104646
MEDIUMCVSS 6.8NVD feed
Published 8 October 2026 · tracked since 8 October 2026
Description
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbit
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107573 HIGH 7.8
- CVE-2026-107275 MEDIUM 6.8
- CVE-2026-93509 MEDIUM 6.5
- CVE-2026-104660 HIGH 7.8
- CVE-2026-104671 MEDIUM 5.3
- CVE-2026-105190 MEDIUM 5.3
- CVE-2026-103649 HIGH 7.5
- CVE-2026-103010 HIGH 7.8
- CVE-2026-103011 MEDIUM 6.5
- CVE-2026-103517 MEDIUM 5.3