SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-24628

MEDIUM · CVSS 5.9 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Photo Gallery by Supsystic versions up to 1.16.3 are vulnerable to a Cross Site Scripting (XSS) attack, allowing attackers to inject malicious scripts that can be executed in the context of an administrator's session. This vulnerability could lead to unauthorized actions being performed on behalf of the administrator, potentially compromising the integrity of the application. Website administrators using affected versions should prioritize applying updates to mitigate this risk.

CVE
CVE-2026-24628
Severity
MEDIUM
CVSS
5.9
EPSS
0.17%

Original NVD Description

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.