First published: Mon Feb 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Gallery allows Stored XSS. This issue affects Gallery: from n/a through 2.2.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Gallery | <=2.2.1 | |
WordPress Gallery Custom Links Plugin | <=2.2.1 |
Update the WordPress Gallery wordpress plugin to the latest available version (at least 2.2.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26778 is classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
To fix CVE-2025-26778, update NotFound Gallery or the WordPress Gallery Custom Links Plugin to a version higher than 2.2.1, which patches this vulnerability.
CVE-2025-26778 affects NotFound Gallery versions up to 2.2.1 and the WordPress Gallery Custom Links Plugin versions up to 2.2.1.
CVE-2025-26778 is a stored Cross-site Scripting (XSS) vulnerability caused by improper neutralization of input during web page generation.
If you are using an affected version of NotFound Gallery or the WordPress Gallery Custom Links Plugin, your application is susceptible to exploitation via CVE-2025-26778.