๐Ÿ” CVE Alert

CVE-2026-42028

MEDIUM 5.3

novaGallery: Unauthenticated Path Traversal in Album and Cached Image Routes Allows Reading Images Outside Gallery Root

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1.

CWE CWE-22
Vendor novafacile
Product novagallery
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for novafacile novagallery

Be the first to know when new medium vulnerabilities affecting novafacile novagallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

novafacile / novagallery
< 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/novafacile/novagallery/security/advisories/GHSA-wv5j-98c7-frm9 github.com: https://github.com/novafacile/novagallery/commit/46fe7b0f79f429e18c8cff3f92360c4513732ba6 github.com: https://github.com/novafacile/novagallery/releases/tag/v2.1.1