Show filters
78 Total Results
Displaying 1-10 of 78
Sort by:
Attacker Value
Unknown

CVE-2024-37246

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jethin Gallery Slideshow allows Stored XSS.This issue affects Gallery Slideshow: from n/a through 1.4.1.
Attacker Value
Unknown

CVE-2023-41876

Disclosure Date: October 10, 2023 (last updated October 12, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Hardik Kalathiya WP Gallery Metabox plugin <= 1.0.0 versions.
Attacker Value
Unknown

CVE-2023-25473

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.
Attacker Value
Unknown

CVE-2023-2562

Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post.
Attacker Value
Unknown

CVE-2023-2561

Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
Attacker Value
Unknown

CVE-2023-37152

Disclosure Date: July 10, 2023 (last updated May 17, 2024)
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
Attacker Value
Unknown

CVE-2022-47134

Disclosure Date: May 20, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions.
Attacker Value
Unknown

CVE-2023-2776

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-23676

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5.3 versions.
Attacker Value
Unknown

CVE-2023-26016

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions.