Robogallery maintains a narrowly focused portfolio centered on image gallery and media display products, whose web-facing application surface exposes a concentrated set of input-handling and access-control weaknesses. The recurring vulnerability pattern clusters around cross-site scripting and cross-site request forgery issues alongside improper authorization logic, characteristic of web application frameworks handling user-submitted content and session management. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Robogallery over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41785MEDIUM Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions. | Mar 21, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-27620MEDIUM Auth. (contributor+) Stored Cross-site Scripting (XSS) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.12 versions. | Apr 7, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-45804MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugi | Mar 1, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-3896MEDIUM The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and | Jul 24, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-22295MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery allows Stored XSS. | Jan 31, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-3499MEDIUM The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such | Sep 4, 2023 | 4.8 | 16 | NO | NO |
CVE-2019-25149MEDIUM The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any cap | Jun 7, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Robogallery.
Media articles that mention a CVE ID that affects a product developed by Robogallery — matched by CVE ID, not by vendor name.