Cross-Site Scripting Vulnerability in Robo Gallery by Robosoft
CVE-2026-32356

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32356?

A Cross-Site Scripting (XSS) vulnerability exists in Robo Gallery, a product by Robosoft, which allows the injection of malicious scripts into web pages. This vulnerability, found in versions up to and including 5.1.2, can lead to unauthorized actions performed on behalf of users, potentially compromising sensitive information and user sessions.

Affected Version(s)

Robo Gallery 0 <= 5.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.