Show filters
286 Total Results
Displaying 51-60 of 286
Sort by:
Attacker Value
Unknown

CVE-2023-2776

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-23676

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5.3 versions.
Attacker Value
Unknown

CVE-2023-26016

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions.
Attacker Value
Unknown

CVE-2014-125096

Disclosure Date: April 10, 2023 (last updated October 20, 2023)
A vulnerability was found in Fancy Gallery Plugin 1.5.12 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file class.options.php of the component Options Page. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.13 is able to address this issue. The identifier of the patch is fdf1f9e5a1ec738900f962e69c6fa4ec6055ed8d. It is recommended to upgrade the affected component. The identifier VDB-225349 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-27620

Disclosure Date: April 07, 2023 (last updated November 08, 2023)
Auth. (contributor+) Stored Cross-site Scripting (XSS) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.12 versions.
Attacker Value
Unknown

CVE-2023-0441

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.
Attacker Value
Unknown

CVE-2022-41785

Disclosure Date: March 21, 2023 (last updated November 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions.
Attacker Value
Unknown

CVE-2023-27040

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
Attacker Value
Unknown

CVE-2022-45804

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugin deactivate & activate.
Attacker Value
Unknown

CVE-2023-1054

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-221820.