Extension WordPress
Vulnérabilités DZS Video Gallery
Cette page rassemble les failles publiées pour DZS Video Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de DZS Video Gallery
9 fiches
DZS Video Gallery <= 12.39 – Authenticated (Subscriber+) SQL Injection
The DZS Video Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 12.39 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-12.39
12.40
12/01/2026
DZS Video Gallery <= 12.39 – Reflected Cross-Site Scripting
The DZS Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 12.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-12.39
12.40
22/05/2025
DZS Video Gallery <= 12.39 – Authenticated (Subscriber+) PHP Object Injection
The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 12.39 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
*-12.39
12.40
21/05/2025
DZS Video Gallery <= 12.39 – Unauthenticated PHP Object Injection
The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 12.39 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No…
*-12.39
12.40
20/05/2025
DZS Video Gallery <= 8.60 – Reflected Cross-Site Scripting
The DZS Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'initer' parameter in versions up to, and including, 8.60 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-8.60
Non indiqué
11/03/2016
DZS Video Gallery < 7.95 – Limited Local File Inclusion
The DZS Video Gallery plugin for WordPress is vulnerable to remote/local file inclusion in versions up to, and excluding, 7.95. This can allow unauthenticated attackers to retrieve local and remote files with a .swf extension.
[*, 7.95)
7.95
27/09/2014
DZS Video Gallery < 7.95 – Multiple Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter.
[*, 7.95)
7.95
27/09/2014
DZS Video Gallery <= 9.63 – Reflected Cross-Site Scripting
The DZS Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ajax.php 'source' parameter in versions up to, and including 9.63 due to insufficient input sanitization and output escaping. This makes it possible for…
*-9.63
9.64
01/08/2014
DZS Video Gallery < 7.95 – Reflected Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3) preview_allchars.swf, or…
[*, 7.95)
7.95
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.