novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1.
Metrics
Affected Vendors & Products
References
History
Fri, 08 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1. | |
| Title | novaGallery: Unauthenticated Path Traversal in Album and Cached Image Routes Allows Reading Images Outside Gallery Root | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T17:05:04.239Z
Reserved: 2026-04-23T16:05:01.707Z
Link: CVE-2026-42028
Updated: 2026-05-08T17:04:59.767Z
Status : Received
Published: 2026-05-08T17:16:31.177
Modified: 2026-05-08T18:16:33.827
Link: CVE-2026-42028
No data.
OpenCVE Enrichment
Updated: 2026-05-08T20:45:16Z