Show filters
286 Total Results
Displaying 111-120 of 286
Sort by:
Attacker Value
Unknown

CVE-2010-4815

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.
Attacker Value
Unknown

CVE-2013-2631

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
Attacker Value
Unknown

CVE-2012-4919

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
Attacker Value
Unknown

CVE-2012-2931

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
Attacker Value
Unknown

CVE-2014-4553

Disclosure Date: January 02, 2020 (last updated February 21, 2025)
Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.
Attacker Value
Unknown

CVE-2015-9447

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Attacker Value
Unknown

CVE-2015-9446

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
Attacker Value
Unknown

CVE-2015-9445

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
Attacker Value
Unknown

CVE-2016-10940

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Attacker Value
Unknown

CVE-2013-7482

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
0