Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2023-41659
Disclosure Date: October 06, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Jules Colle, BDWM Responsive Gallery Grid plugin <= 2.3.10 versions.
0
Attacker Value
Unknown
CVE-2023-3292
Disclosure Date: July 31, 2023 (last updated October 08, 2023)
The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-0060
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2022-2597
Disclosure Date: September 05, 2022 (last updated February 24, 2025)
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts
0
Attacker Value
Unknown
CVE-2022-2543
Disclosure Date: September 05, 2022 (last updated February 24, 2025)
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts
0
Attacker Value
Unknown
CVE-2021-25090
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed
0
Attacker Value
Unknown
CVE-2022-0186
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard
0
Attacker Value
Unknown
CVE-2021-24529
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-14962
Disclosure Date: June 22, 2020 (last updated February 21, 2025)
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2013-4117
Disclosure Date: July 16, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
0