CVE-2021-47929

Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed, affecting all users viewing the page.
Configurations

No configuration.

History

24 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Filterable Portfolio Gallery 1.0 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar JavaScript malicioso al introducir payloads en el campo de título. Los atacantes pueden almacenar código JavaScript como etiquetas de imagen con manejadores onerror que se ejecutan cuando se previsualiza la galería, afectando a todos los usuarios que ven la página.

10 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-10 13:16

Updated : 2026-07-25 10:10


NVD link : CVE-2021-47929

Mitre link : CVE-2021-47929

CVE.ORG link : CVE-2021-47929


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')