Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
codeasily grand flagallery vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2014-8491
The Grand Flagallery plugin prior to 4.25 for WordPress allows remote malicious users to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-album-gallery/skins/banner_widget_default/gallery.php.
Codeasily Grand Flagallery
NA
CVE-2011-4624
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) prior to 1.57 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the i parameter.
Codeasily Grand Flagallery
4.8
CVSSv3
CVE-2021-24903
The GRAND FlaGallery WordPress plugin up to and including 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.
Codeasily Grand Flagallery
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started