Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gallery project vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2023-0151
The uTubeVideo Gallery WordPress plugin prior to 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site S...
Utubevideo Gallery Project Utubevideo Gallery
5.4
CVSSv3
CVE-2022-4783
The Youtube Channel Gallery WordPress plugin up to and including 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store...
Youtube Channel Gallery Project Youtube Channel Gallery
5.4
CVSSv3
CVE-2022-4651
The Justified Gallery WordPress plugin prior to 1.7.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Justified Gallery Project Justified Gallery
5.4
CVSSv3
CVE-2022-3991
The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters saved via the update() function in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping. This makes it possible for auth...
Photospace Gallery Project Photospace Gallery
4.8
CVSSv3
CVE-2023-26016
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions.
Simple Portfolio Gallery Project Simple Portfolio Gallery 0.1
4.8
CVSSv3
CVE-2022-4142
The WordPress Filter Gallery Plugin WordPress plugin prior to 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the ...
Wordpress Filter Gallery Project Wordpress Filter Gallery
4.8
CVSSv3
CVE-2020-28071
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored X...
Alumni Management System Project Alumni Management System 1.0
4.3
CVSSv3
CVE-2023-2561
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level malicious users to modify galleries attached to...
Gallery-metabox Project Gallery-metabox
4.3
CVSSv3
CVE-2023-2562
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level malicious users to obtain a list of images attached ...
Gallery-metabox Project Gallery-metabox
4.3
CVSSv3
CVE-2022-38135
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.
Photospace Gallery Project Photospace Gallery
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »