Junglewise Threat Intelligence

CVE-2026-78238: SOY Gallery cross-site scripting in login

CVE-2026-78238 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Executive brief

SOY Gallery is a web-based image gallery management application. The vulnerability allows an attacker to inject and execute arbitrary JavaScript code in the web browser of users logging into the system, potentially allowing theft of session credentials or other malicious actions performed on behalf of the logged-in user.

Technical details

This is a cross-site scripting (CWE-79) vulnerability in SOY Gallery version 2.0.0 and earlier. The vulnerability requires an authenticated attacker (login credentials required) and user interaction (the victim must be logging in), but no special network access or elevated privileges are needed. An attacker can inject malicious JavaScript that executes in the context of the affected user's browser session, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability was patched in version 2.1.0, released on 2026-08-31.

Affected products

  • Tsuyoshi Saito SOY Gallery 2.0.0 and earlier

Timeline

  • 2026-08-28: disclosed
  • 2026-08-31: patched: Version 2.1.0 released

References