Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gallery vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2016-11018
An issue exists in the Huge-IT gallery-images plugin prior to 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
Huge-it Image Gallery
7.5
CVSSv2
CVE-2019-16119
SQL injection in the photo-gallery (10Web Photo Gallery) plugin prior to 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
10web Photo Gallery
1 EDB exploit
1 Github repository
7.5
CVSSv2
CVE-2019-14314
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin prior to 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote malicious user to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display...
Imagely Nextgen Gallery
1 Github repository
7.5
CVSSv2
CVE-2016-10921
The gallery-photo-gallery plugin prior to 1.0.1 for WordPress has SQL injection.
Ays-pro Photo Gallery
7.5
CVSSv2
CVE-2016-10889
The nextgen-gallery plugin prior to 2.1.57 for WordPress has SQL injection via a gallery name.
Imagely Nextgen Gallery
7.5
CVSSv2
CVE-2018-18018
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
Tribulant Slideshow Gallery 1.6.8
7.5
CVSSv2
CVE-2018-11511
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
Asustor Asustor Data Master 3.1.0
1 EDB exploit
7.5
CVSSv2
CVE-2018-5981
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
Web-dorado Gallery Wd 1.3.6
1 EDB exploit
7.5
CVSSv2
CVE-2017-17872
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
Jextn Jextn Video Gallery 3.0.5
1 EDB exploit
7.5
CVSSv2
CVE-2017-14125
SQL injection vulnerability in the Responsive Image Gallery plugin prior to 1.2.1 for WordPress allows remote malicious users to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
Wpdevart Responsive Image Gallery Gallery Album
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »