Extension WordPress
Vulnérabilités Album and Image Gallery with Lightbox – Flagallery Photo Portfolio
Cette page rassemble les failles publiées pour Album and Image Gallery with Lightbox – Flagallery Photo Portfolio, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Album and Image Gallery with Lightbox – Flagallery Photo Portfolio
14 fiches
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 6.1.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when…
*-6.1.2
Non indiqué
12/11/2021
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 4.25 – Sensitive Data Exposure
The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-album-gallery/skins/banner_widget_default/gallery.php.
[*, 4.25)
4.25
30/10/2014
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 0.59 – SQL Injection
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'pid' parameter in the 'lib/hitcounter.php' in versions up to, and including, 0.59 due to insufficient escaping…
*-0.59
0.60
01/08/2014
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.72 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
*-2.71
2.72
01/08/2014
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.55 – SQL Injection
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ' $id' variable in the lib/shortcodes.php file in versions up to, and including, 2.55 due to insufficient…
*-2.55
2.56
25/03/2013
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 – SQL Injection
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the lib/shortcodes.php file in versions up to, and including, 2.00 due to insufficient escaping…
*-2.00
2.10
24/12/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 – SQL Injection
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ‘form’ parameter in the admin/ajax.php file in versions up to, and including, 2.00 due to insufficient escaping…
[*, 2.10)
2.10
24/12/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 – Arbitrary File Modification
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file modification in versions up to, and including, 2.00. This is due to unsanitized user input on the 'settingsXML', and…
*-2.00
2.10
24/12/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 3.1.0 – Arbitrary File Deletion
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 3.0.1 via the 'delete' parameter. This makes it possible…
[*, 3.1.0)
3.1.0
24/12/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.53 – SQL Injection
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'description' parameter in the admin/manage.php file in versions up to 2.53 due to insufficient escaping on…
[*, 2.53)
2.53
24/12/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.53 – Sensitive Information Disclosure
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.52 via the 'dir' parameter in the admin/ajax.php file, the 'want2read' parameter…
[*, 2.53)
2.53
24/12/2012
SWFUpload <= 2.2.0.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter,…
[*, 2.12)
2.12
09/11/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 1.72 – Reflected Cross-Site Scripting
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'skin' parameter in versions up to, and including, 1.72 due to insufficient input sanitization and output…
*-1.72
1.73
15/05/2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 1.57 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
[*, 1.57)
1.57
30/11/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.