N/A
2026-04-20< 2.1.5
InPost Gallery <= 2.1.4.6 - Unauthenticated SQL Injection
Minimum safe version
2.1.5
Update to 2.1.5 or later to address 11 fixable vulnerabilities
InPost Gallery <= 2.1.4.6 - Unauthenticated SQL Injection
CVE-2025-57889
CVE-2025-26903
CVE-2024-11002
InPost Gallery <= 2.1.2 - LFI & Authenticated Stored XSS
WordPress InPost Gallery Plugin <= 2.1.4.1 is vulnerable to Cross Site Scripting (XSS)
InPost Gallery <= 2.1.2 - Cross-Site Scripting
InPost Gallery < 2.1.2.1 - Local File Inclusion
CVE-2022-4063
WordPress InPost Gallery Plugin <= 2.1.2 - Local File Inclusion (LFI) Vulnerability
WordPress InPost Gallery plugin <= 2.1.2 - Authenticated Persistent Cross-Site (XSS) Vulnerability