SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66448

MEDIUM · CVSS 6.5 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Gallery PhotoBlocks versions up to 1.3.3 are vulnerable to a Contributor Cross Site Scripting (XSS) attack, allowing attackers to inject malicious scripts through user-generated content. This could lead to unauthorized access to sensitive information or manipulation of user sessions. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-66448
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%

Original NVD Description

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.