Show filters
286 Total Results
Displaying 101-110 of 286
Sort by:
Attacker Value
Unknown
CVE-2021-24667
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of image parameters in meta data.
0
Attacker Value
Unknown
CVE-2021-38753
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
0
Attacker Value
Unknown
CVE-2021-24349
Disclosure Date: June 14, 2021 (last updated February 22, 2025)
This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.
0
Attacker Value
Unknown
CVE-2021-24126
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2020-35582
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php request with the post_title parameter.
0
Attacker Value
Unknown
CVE-2020-35581
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php request with the meta[title] parameter.
0
Attacker Value
Unknown
CVE-2020-28688
Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
0
Attacker Value
Unknown
CVE-2020-28687
Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
0
Attacker Value
Unknown
CVE-2020-5616
Disclosure Date: August 04, 2020 (last updated February 21, 2025)
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-9334
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
0