Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2016-1000116

Disclosure Date: October 21, 2016 (last updated February 15, 2024)
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
0
Attacker Value
Unknown

CVE-2016-1000113

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
Attacker Value
Unknown

CVE-2016-1000114

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
XSS in huge IT gallery v1.1.5 for Joomla
Attacker Value
Unknown

CVE-2014-2333

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-2458

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.
0
Attacker Value
Unknown

CVE-2007-2457

Disclosure Date: May 02, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.
0