Show filters
286 Total Results
Displaying 41-50 of 286
Sort by:
Attacker Value
Unknown

CVE-2023-25473

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.
Attacker Value
Unknown

CVE-2023-2562

Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post.
Attacker Value
Unknown

CVE-2023-2561

Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
Attacker Value
Unknown

CVE-2023-34185

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
Attacker Value
Unknown

CVE-2023-37152

Disclosure Date: July 10, 2023 (last updated May 17, 2024)
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
Attacker Value
Unknown

CVE-2023-28784

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions.
Attacker Value
Unknown

CVE-2023-35098

Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
Attacker Value
Unknown

CVE-2022-45827

Disclosure Date: June 12, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions.
Attacker Value
Unknown

CVE-2019-25149

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary to site functionality or security.
Attacker Value
Unknown

CVE-2022-47134

Disclosure Date: May 20, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Bill Erickson Gallery Metabox plugin <= 1.5 versions.