Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Enviragallery

First CVE: Feb 25, 2020Active for: 6 yearsTotal CVEs: 8

Enviragallery maintains a gallery and media-management plugin that, despite narrow product scope, occupies a notable position in the WordPress ecosystem where it serves a wide deployment base. The vulnerability profile concentrates in the Envira Gallery plugin and recurs through web-application weakness classes including cross-site scripting in page generation, missing authorization checks, and improper handling of exceptional conditions—characteristic of plugins that process user-supplied content and manage access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Enviragallery over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 25, 2020
6 years ago
Most Recent CVE
Nov 1, 2024
630 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-43925HIGH
Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Ph
Nov 1, 20248.823NONO
CVE-2022-2190MEDIUM
The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflecte
Oct 31, 20226.122NONO
CVE-2020-35582MEDIUM
A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php reque
Jan 15, 20215.420NONO
CVE-2020-35581MEDIUM
A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php
Jan 15, 20215.420NONO
CVE-2020-9334MEDIUM
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-priv
Feb 25, 20205.420NONO
CVE-2021-24126MEDIUM
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) bef
Mar 18, 20215.419NONO
CVE-2024-3899MEDIUM
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such a
Sep 11, 20244.816NONO
CVE-2023-6742MEDIUM
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_g
Jan 11, 20244.316NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
88%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (25.0%)
Unknown0 (0.0%)
Required6 (75.0%)
Privileges Required
Low6 (75.0%)
High1 (12.5%)
None1 (12.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Enviragallery.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Enviragallery — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Enviragallery's Products

View all 4 CNAs →

Top CWEs