Show filters
286 Total Results
Displaying 111-120 of 286
Sort by:
Attacker Value
Unknown
CVE-2010-4815
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.
0
Attacker Value
Unknown
CVE-2013-2631
Disclosure Date: February 03, 2020 (last updated February 21, 2025)
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
0
Attacker Value
Unknown
CVE-2012-4919
Disclosure Date: January 22, 2020 (last updated February 21, 2025)
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
0
Attacker Value
Unknown
CVE-2012-2931
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
0
Attacker Value
Unknown
CVE-2014-4553
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown
CVE-2015-9447
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
0
Attacker Value
Unknown
CVE-2015-9446
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2015-9445
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
0
Attacker Value
Unknown
CVE-2016-10940
Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
0
Attacker Value
Unknown
CVE-2013-7482
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
0