CVE-2026-3070

MEDIUM

SourceCodester Modern Image Gallery App 1.0 - XSS

Title source: llm
STIX 2.1

Description

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

References (5)

Core 5
Core References
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.757768
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.347425
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.347425
Issue Tracking exploit issue-tracking
https://github.com/tiancesec/CVE/issues/28
Various Sources product
https://www.sourcecodester.com/

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 17.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
remyandrade/modern_image_gallery_app 1.0
Published Feb 24, 2026
Tracked Since Feb 24, 2026