Show filters
78 Total Results
Displaying 31-40 of 78
Sort by:
Attacker Value
Unknown

CVE-2020-28688

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2020-28687

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2012-4919

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
Attacker Value
Unknown

CVE-2014-4553

Disclosure Date: January 02, 2020 (last updated February 21, 2025)
Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.
Attacker Value
Unknown

CVE-2016-10940

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Attacker Value
Unknown

CVE-2013-7482

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2015-9327

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The flickr-justified-gallery plugin before 3.4.0 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2017-17869

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
0
Attacker Value
Unknown

CVE-2015-5682

Disclosure Date: May 23, 2017 (last updated November 26, 2024)
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.
0
Attacker Value
Unknown

CVE-2016-1000153

Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin tidio-gallery v1.1
0