What the vulnerability does
01Description
Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.
Explanation of Vulnerability in Simple Terms
02Summary
SimpLy Gallery versions 3.3.2 and earlier contain a privilege escalation vulnerability affecting multiple security functions. An authenticated user with low privileges can modify system settings, alter data, or disrupt service availability across the application. The vulnerability requires network access and valid login credentials but no additional user interaction.
What an attacker can do
03Attacker Capabilities
Modify gallery settings, alter or delete content, and disrupt service availability with a low-privilege account.
Potential impact on your site
04Site Impact
Authenticated users can escalate privileges to modify critical settings, compromise gallery content, and cause service disruption.
Conditions required to exploit
05Prerequisites
Valid login credentials with low-level user privileges; network access to the application.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated