Show filters
82 Total Results
Displaying 71-80 of 82
Sort by:
Attacker Value
Unknown

CVE-2019-16118

Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
Attacker Value
Unknown

CVE-2015-9380

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
0
Attacker Value
Unknown

CVE-2019-14797

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
0
Attacker Value
Unknown

CVE-2019-14798

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
0
Attacker Value
Unknown

CVE-2019-14313

Disclosure Date: July 30, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
Attacker Value
Unknown

CVE-2019-10866

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
0
Attacker Value
Unknown

CVE-2019-11590

Disclosure Date: April 29, 2019 (last updated November 27, 2024)
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
0
Attacker Value
Unknown

CVE-2015-2324

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-9312

Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
0
Attacker Value
Unknown

CVE-2017-12977

Disclosure Date: August 21, 2017 (last updated November 26, 2024)
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
0