Show filters
78 Total Results
Displaying 41-50 of 78
Sort by:
Attacker Value
Unknown

CVE-2015-1000007

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Remote file download vulnerability in wptf-image-gallery v1.03
0
Attacker Value
Unknown

CVE-2015-7527

Disclosure Date: December 17, 2015 (last updated October 05, 2023)
lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gallery Settings" page.
0
Attacker Value
Unknown

CVE-2015-5599

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.
0
Attacker Value
Unknown

CVE-2015-4133

Disclosure Date: May 28, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
0
Attacker Value
Unknown

CVE-2014-9441

Disclosure Date: January 02, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting (XSS) attacks via the (2) ll__opt[image2_url] or (3) ll__opt[image3_url] parameter in a ll_save_settings action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-6315

Disclosure Date: October 10, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2014-5201

Disclosure Date: August 12, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown

CVE-2012-6653

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.
0
Attacker Value
Unknown

CVE-2014-5186

Disclosure Date: August 06, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit action in the allvideogallery_videos page to wp-admin/admin.php.
0
Attacker Value
Unknown

CVE-2014-4529

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
0