Extension WordPress

Vulnérabilités Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Cette page rassemble les failles publiées pour Album and Image Gallery with Lightbox – Flagallery Photo Portfolio, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
1Critiques
13Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

14 fiches

CVE-2021-24903 Moyenne · 5,5
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 6.1.2 – Authenticated (Admin+) Stored Cross-Site Scripting

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when…

Versions affectées

*-6.1.2

Correctif

Non indiqué

Publication

12/11/2021

CVE-2014-8491 Moyenne · 5,3
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 4.25 – Sensitive Data Exposure

The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-album-gallery/skins/banner_widget_default/gallery.php.

Versions affectées

[*, 4.25)

Correctif

4.25

Publication

30/10/2014

Vulnérabilité Critique · 9,8
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 0.59 – SQL Injection

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'pid' parameter in the 'lib/hitcounter.php' in versions up to, and including, 0.59 due to insufficient escaping…

Versions affectées

*-0.59

Correctif

0.60

Publication

01/08/2014

CVE-2013-3261 Moyenne · 6,1
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.72 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.

Versions affectées

*-2.71

Correctif

2.72

Publication

01/08/2014

Vulnérabilité Élevée · 7,2
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.55 – SQL Injection

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ' $id' variable in the lib/shortcodes.php file in versions up to, and including, 2.55 due to insufficient…

Versions affectées

*-2.55

Correctif

2.56

Publication

25/03/2013

Vulnérabilité Élevée · 8,8
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 – SQL Injection

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the lib/shortcodes.php file in versions up to, and including, 2.00 due to insufficient escaping…

Versions affectées

*-2.00

Correctif

2.10

Publication

24/12/2012

Vulnérabilité Élevée · 7,2
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 – SQL Injection

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ‘form’ parameter in the admin/ajax.php file in versions up to, and including, 2.00 due to insufficient escaping…

Versions affectées

[*, 2.10)

Correctif

2.10

Publication

24/12/2012

Vulnérabilité Moyenne · 4,9
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 – Arbitrary File Modification

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file modification in versions up to, and including, 2.00. This is due to unsanitized user input on the 'settingsXML', and…

Versions affectées

*-2.00

Correctif

2.10

Publication

24/12/2012

Vulnérabilité Élevée · 7,2
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 3.1.0 – Arbitrary File Deletion

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 3.0.1 via the 'delete' parameter. This makes it possible…

Versions affectées

[*, 3.1.0)

Correctif

3.1.0

Publication

24/12/2012

Vulnérabilité Élevée · 7,2
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.53 – SQL Injection

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'description' parameter in the admin/manage.php file in versions up to 2.53 due to insufficient escaping on…

Versions affectées

[*, 2.53)

Correctif

2.53

Publication

24/12/2012

Vulnérabilité Moyenne · 4,9
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.53 – Sensitive Information Disclosure

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.52 via the 'dir' parameter in the admin/ajax.php file, the 'want2read' parameter…

Versions affectées

[*, 2.53)

Correctif

2.53

Publication

24/12/2012

CVE-2012-3414 Moyenne · 6,1
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

SWFUpload <= 2.2.0.1 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter,…

Versions affectées

[*, 2.12)

Correctif

2.12

Publication

09/11/2012

Vulnérabilité Moyenne · 6,1
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 1.72 – Reflected Cross-Site Scripting

The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'skin' parameter in versions up to, and including, 1.72 due to insufficient input sanitization and output…

Versions affectées

*-1.72

Correctif

1.73

Publication

15/05/2012

CVE-2011-4624 Moyenne · 6,1
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio

Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 1.57 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

Versions affectées

[*, 1.57)

Correctif

1.57

Publication

30/11/2011

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités