Robosoft's vulnerability profile centers on web-facing gallery and mapping applications, a niche product portfolio that recurs with application-layer input-handling weaknesses such as cross-site scripting and cross-site request forgery. These are durable characteristics of web application design rather than indicators of broad systemic risk, and the vendor's modest disclosure volume reflects its focused scope. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Robosoft over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24414HIGH Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.11 versions. | May 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-2279MEDIUM The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, whic | Apr 4, 2025 | 5.9 | 17 | NO | NO |
CVE-2024-49696MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo G | Oct 24, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-13384MEDIUM The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such | May 15, 2025 | 4.8 | 15 | NO | NO |
CVE-2024-10144MEDIUM The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such | May 15, 2025 | 4.8 | 15 | NO | NO |
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege us | Jan 7, 2025 | 2.7 | 13 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Robosoft.
Media articles that mention a CVE ID that affects a product developed by Robosoft — matched by CVE ID, not by vendor name.