Sceawere
Vulnerability Detail
CVE-2026-105887UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Robo Gallery Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- Robosoft
- Product
- Robo Gallery
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through 5.1.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T13:17:13.640Z",
"pubdate": "2026-10-08T13:17:13.640Z",
"executiveSummary": "The Robo Gallery plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability exists within versions 5.1.6 and earlier, allowing an authenticated attacker with sufficient privileges to inject malicious scripts into the application.\nThe flaw allows the execution of arbitrary JavaScript in the context of a victim's browser session when they view the affected gallery page.\nThe primary risk involves the unauthorized execution of client-side code, which may lead to session hijacking, credential theft, unauthorized actions performed on behalf of the user, or unauthorized redirection.\nExploitation requires an attacker to possess the necessary permissions to interact with the plugin's configuration or content management interface to inject the malicious payload, which is then stored persistently within the database.",
"technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nThe root cause of the vulnerability lies in the insufficient sanitization and validation of input parameters processed by the Robo Gallery plugin before they are stored in the database and subsequently reflected in the web application's output.\nThe exploitation flow begins when an attacker, typically an authenticated user such as an administrator or contributor with access to the plugin's interface, supplies specially crafted malicious input into fields intended for gallery settings or content. Because the application fails to adequately encode or neutralize this data, the payload is persisted into the database.\nWhen a user or administrator navigates to a web page where the Robo Gallery is rendered, the application retrieves the stored, malicious payload from the database and embeds it directly into the HTML response without appropriate context-aware output encoding.\nThe browser interprets the injected data as legitimate executable script code rather than plain text. This permits the execution of arbitrary JavaScript within the security context of the victim's session.\nThe attack is persistent; every user who visits the page containing the affected gallery will trigger the execution of the payload. The capabilities of the injected script are limited only by the permissions of the victim; if an administrator views the gallery, the attacker can perform actions that the administrator is authorized to execute, such as modifying plugin configurations, creating new administrative accounts, or injecting additional malicious content into other areas of the WordPress installation.\nPost-exploitation impact includes, but is not limited to, unauthorized access to sensitive data (cookies, session tokens, or CSRF tokens), complete takeover of the victim's session, or malicious redirection of users to external sites controlled by the attacker. Since the vulnerability is stored within the database, the malicious script remains active until manually removed or until the plugin is remediated."
}