What is CVE-2026-24628?
CVE-2026-24628 is an Administrator Cross Site Scripting (XSS) vulnerability found in the Photo Gallery by Supsystic plugin, affecting versions 1.16.3 and earlier. It allows specially crafted scripts to be executed within the admin panel. Updating to the latest version of the plugin is recommended.
Azərbaycanca: CVE-2026-24628, Supsystic-in Photo Gallery plagininin 1.16.3 və daha əvvəl versiyalarında aşkar edilmiş Administrator Cross Site Scripting (XSS) zəifliyidir. Bu boşluq admin panelində xüsusi hazırlanmış skriptin icra olunmasına imkan verir. Plaginin son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin does CVE-2026-24628 affect?
This vulnerability affects the Photo Gallery by Supsystic plugin.
What should I do to protect against CVE-2026-24628?
You should update the Photo Gallery plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.