Show filters
179 Total Results
Displaying 81-90 of 179
Sort by:
Attacker Value
Unknown
CVE-2019-14467
Disclosure Date: November 18, 2019 (last updated November 27, 2024)
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.
0
Attacker Value
Unknown
CVE-2019-16119
Disclosure Date: September 08, 2019 (last updated November 27, 2024)
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
0
Attacker Value
Unknown
CVE-2019-16117
Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
0
Attacker Value
Unknown
CVE-2019-16118
Disclosure Date: September 08, 2019 (last updated November 27, 2024)
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
0
Attacker Value
Unknown
CVE-2015-9380
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2016-10921
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2016-10918
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2019-14797
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
0
Attacker Value
Unknown
CVE-2019-14798
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
0
Attacker Value
Unknown
CVE-2019-14313
Disclosure Date: July 30, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
0