5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1.
Basic Information
ID
CVE-2026-42028
Source
GitHub_M
Published
May 8, 2026 at 15:54
Affected Product
Vendor
novafacile
Product
novagallery
Version
< 2.1.1
Affected Versions
novafacile novagallery < 2.1.1