Show filters
125 Total Results
Displaying 31-40 of 125
Sort by:
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2020-28688

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2020-28687

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2019-14467

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.
Attacker Value
Unknown

CVE-2016-10940

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Attacker Value
Unknown

CVE-2017-1002028

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.
0
Attacker Value
Unknown

CVE-2016-1000124

Disclosure Date: October 06, 2016 (last updated February 15, 2024)
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
0
Attacker Value
Unknown

CVE-2016-1000123

Disclosure Date: October 06, 2016 (last updated February 15, 2024)
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
0
Attacker Value
Unknown

CVE-2015-1000007

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Remote file download vulnerability in wptf-image-gallery v1.03
0
Attacker Value
Unknown

CVE-2015-2983

Disclosure Date: August 22, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in admin.php in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote attackers to hijack the authentication of arbitrary users.
0