CVE-2026-12982

Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.


We have discovered 5,088 live websites that are affected by CVE-2026-12982.

Run a Free Instant Scan




Affected Software

Product  Document Gallery
Category Wordpress Plugins
Vulnerable Domains5,088 live websites (95% of Document Gallery install base)
Vulnerable Versions
  • from 0 through 5.1.1
Vulnerable Versions Count25 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • João Ramos Maciel (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-12982
United States1,205 websites



France1,363 websites
Germany347 websites
GB320 websites
Italy257 websites
Russia126 websites
Canada124 websites
Switzerland104 websites
Netherlands97 websites
Spain89 websites

Website Distribution by TLD

Number of websites using CVE-2026-12982
.com1,458 websites
.fr757 websites
.org661 websites
.de193 websites
.it184 websites
.co.uk153 websites
.ru111 websites
.net107 websites
.ch84 websites
.nl74 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12982

Top websites that are affected by CVE-2026-12982. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.edu United States**,***
**********.de Germany***,***
******.****.edu United States***,***
********.com France***,***
*********.fr France***,***
***.*****.pl Poland***,***
**********.pf French Polynesia***,***
*****.***.ph Philippines***,***
*************.fr France***,***
********.eu France***,***
See full domain list

FAQ

CVE-2026-12982 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Document Gallery
A total of 5,088 websites have been identified as vulnerable to CVE-2026-12982, based on global website indexing conducted by WebTechSurvey.
The Document Gallery is affected by the CVE-2026-12982 vulnerability.
Document Gallery versions up to 5.1.1 are vulnerable to CVE-2026-12982.
CVE-2026-12982 is resolved in version 5.1.1 of Document Gallery.