Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gallery project gallery vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2022-47134
Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions.
Gallery Metabox Project Gallery Metabox
5.4
CVSSv3
CVE-2022-4651
The Justified Gallery WordPress plugin prior to 1.7.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Justified Gallery Project Justified Gallery
6.1
CVSSv3
CVE-2013-7482
The reflex-gallery plugin prior to 1.4.3 for WordPress has XSS.
Reflex Gallery Project Reflex Gallery
5.4
CVSSv3
CVE-2023-23676
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5.3 versions.
File Gallery Project File Gallery
4.3
CVSSv3
CVE-2023-2561
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level malicious users to modify galleries attached to...
Gallery-metabox Project Gallery-metabox
4.3
CVSSv3
CVE-2023-2562
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level malicious users to obtain a list of images attached ...
Gallery-metabox Project Gallery-metabox
5.4
CVSSv3
CVE-2023-0151
The uTubeVideo Gallery WordPress plugin prior to 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site S...
Utubevideo Gallery Project Utubevideo Gallery
6.1
CVSSv3
CVE-2016-1000153
Reflected XSS in wordpress plugin tidio-gallery v1.1
Tidio-gallery Project Tidio-gallery
NA
CVE-2015-4133
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin prior to 3.1.4 for WordPress allows remote malicious users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to t...
Reflex Gallery Project Reflex Gallery
1 EDB exploit
4.3
CVSSv3
CVE-2022-38135
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.
Photospace Gallery Project Photospace Gallery
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »