Show filters
286 Total Results
Displaying 121-130 of 286
Sort by:
Attacker Value
Unknown
CVE-2015-9327
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-5974
Disclosure Date: July 05, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-14478
Disclosure Date: May 07, 2019 (last updated November 08, 2023)
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
0
Attacker Value
Unknown
CVE-2014-5014
Disclosure Date: April 25, 2018 (last updated November 26, 2024)
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
0
Attacker Value
Unknown
CVE-2014-4612
Disclosure Date: March 16, 2018 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-17869
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
0
Attacker Value
Unknown
CVE-2017-16635
Disclosure Date: November 06, 2017 (last updated November 26, 2024)
In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-privilege user accounts for backend access are able to inject malicious script codes into the `TWG Explorer` item listing. The request method to inject is POST and the attack vector is located on the application-side of the service. The injection point is the add/create input field and the execution point occurs in the item listing after the add or create.
0
Attacker Value
Unknown
CVE-2015-5682
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.
0
Attacker Value
Unknown
CVE-2016-1000153
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin tidio-gallery v1.1
0
Attacker Value
Unknown
CVE-2015-1000007
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Remote file download vulnerability in wptf-image-gallery v1.03
0