CVE-2026-65475

WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.


We have discovered 4,645 live websites that are affected by CVE-2026-65475.

Run a Free Instant Scan




Affected Software

Product  Modula Best Grid Gallery
Category Wordpress Plugins
Vulnerable Domains4,645 live websites (43% of Modula Best Grid Gallery install base)
Vulnerable Versions
  • from 2.14.25 through 2.14.30
Vulnerable Versions Count6 versions ( 3.92% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Abdullah Kareem "cyberkareem" | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-65475
United States1,333 websites



Germany806 websites
France312 websites
GB281 websites
Italy212 websites
Netherlands182 websites
Poland157 websites
Switzerland132 websites
Spain127 websites
Canada116 websites

Website Distribution by TLD

Number of websites using CVE-2026-65475
.com1,891 websites
.de561 websites
.co.uk216 websites
.org193 websites
.nl169 websites
.it147 websites
.pl125 websites
.fr125 websites
.ch103 websites
.net88 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65475

Top websites that are affected by CVE-2026-65475. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States**,***
***********.org United States**,***
**********.**.**.uk GB***,***
*************.com France***,***
****.org United States***,***
**************.de Germany***,***
*****************.com United States***,***
********.com United States***,***
*****************.com United States***,***
***********.org United States***,***
See full domain list

FAQ

CVE-2026-65475 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Modula Best Grid Gallery
A total of 4,645 websites have been identified as vulnerable to CVE-2026-65475, based on global website indexing conducted by WebTechSurvey.
The Modula Best Grid Gallery is affected by the CVE-2026-65475 vulnerability.
Modula Best Grid Gallery versions up to and including 2.14.30 are vulnerable to CVE-2026-65475.