Show filters
52 Total Results
Displaying 41-50 of 52
Sort by:
Attacker Value
Unknown

CVE-2022-45831

Disclosure Date: March 28, 2023 (last updated November 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
Attacker Value
Unknown

CVE-2023-0441

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.
Attacker Value
Unknown

CVE-2022-4682

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-4465

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The WP Video Lightbox WordPress plugin before 1.9.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
Attacker Value
Unknown

CVE-2022-2189

Disclosure Date: July 25, 2022 (last updated October 07, 2023)
The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Attacker Value
Unknown

CVE-2022-0648

Disclosure Date: March 14, 2022 (last updated October 07, 2023)
The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Attacker Value
Unknown

CVE-2022-0161

Disclosure Date: March 14, 2022 (last updated October 07, 2023)
The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-24667

Disclosure Date: August 30, 2021 (last updated November 28, 2024)
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of image parameters in meta data.
Attacker Value
Unknown

CVE-2021-24665

Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2016-10865

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
0