Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2018-18018
Disclosure Date: April 15, 2019 (last updated November 27, 2024)
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
0
Attacker Value
Unknown
CVE-2018-18019
Disclosure Date: April 15, 2019 (last updated November 27, 2024)
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
0
Attacker Value
Unknown
CVE-2018-18017
Disclosure Date: April 15, 2019 (last updated November 27, 2024)
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
0
Attacker Value
Unknown
CVE-2019-6117
Disclosure Date: April 09, 2019 (last updated November 27, 2024)
The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function.
0
Attacker Value
Unknown
CVE-2015-9228
Disclosure Date: September 12, 2017 (last updated November 26, 2024)
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
0
Attacker Value
Unknown
CVE-2014-2558
Disclosure Date: May 06, 2014 (last updated October 05, 2023)
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
0
Attacker Value
Unknown
CVE-2013-3478
Disclosure Date: March 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid parameter to index.php.
0
Attacker Value
Unknown
CVE-2013-3261
Disclosure Date: June 01, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
0
Attacker Value
Unknown
CVE-2010-4353
Disclosure Date: January 25, 2011 (last updated October 04, 2023)
Unrestricted file upload vulnerability in modules/gallery/models/item.php in Menalto Gallery before 3.0 and beta allows remote authenticated users with upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
0