Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2017-17872

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
0
Attacker Value
Unknown

CVE-2013-2087

Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.
0
Attacker Value
Unknown

CVE-2013-2138

Disclosure Date: October 10, 2013 (last updated October 05, 2023)
The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.
0
Attacker Value
Unknown

CVE-2013-2241

Disclosure Date: October 10, 2013 (last updated October 05, 2023)
modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
0
Attacker Value
Unknown

CVE-2013-2240

Disclosure Date: October 10, 2013 (last updated October 05, 2023)
lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.
0
Attacker Value
Unknown

CVE-2013-5962

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.
0
Attacker Value
Unknown

CVE-2012-4342

Disclosure Date: August 15, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4343

Disclosure Date: August 15, 2012 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Gallery 3 before 3.0.4 allow attackers to execute arbitrary PHP code via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-2405

Disclosure Date: April 22, 2012 (last updated October 04, 2023)
Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.
0