Show filters
67 Total Results
Displaying 1-10 of 67
Sort by:
Attacker Value
Unknown
CVE-2023-51978
Disclosure Date: January 12, 2024 (last updated January 21, 2024)
In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2016-1000115
Disclosure Date: October 21, 2016 (last updated February 15, 2024)
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
0
Attacker Value
Unknown
CVE-2016-1000116
Disclosure Date: October 21, 2016 (last updated February 15, 2024)
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
0
Attacker Value
Unknown
CVE-2016-1000113
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
0
Attacker Value
Unknown
CVE-2016-1000114
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
XSS in huge IT gallery v1.1.5 for Joomla
0
Attacker Value
Unknown
CVE-2014-6315
Disclosure Date: October 10, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2014-2558
Disclosure Date: May 06, 2014 (last updated October 05, 2023)
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
0
Attacker Value
Unknown
CVE-2014-2333
Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2013-3261
Disclosure Date: June 01, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
0