CVE-2017-16356: Kubik-Rubik Simple Image Gallery Extended

Medium severity, CVSS 6.1. EPSS: 2.2% chance of exploitation in the next 30 days.

Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.

Affected products

  • Kubik-Rubik Simple Image Gallery Extended: before 3.3.0 (fixed in 3.3.0)

Published 2018-02-20. Last modified 2026-06-17.