Extension WordPress
Vulnérabilités Gallery Bank – WordPress Photo Gallery Plugin
Cette page rassemble les failles publiées pour Gallery Bank – WordPress Photo Gallery Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gallery Bank – WordPress Photo Gallery Plugin
9 fiches
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.0.18
4.0.19
18/07/2023
Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 – Stored Cross-Site Scripting via Gallery Description
The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Gallery Description in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.
*-4.0.50
Non indiqué
09/06/2022
Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 – Stored Cross-Site Scripting via Media Upload
The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media upload module in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.
*-4.0.50
Non indiqué
09/06/2022
Gallery Bank – WordPress Photo Gallery Plugin <= 3.0.229 – SQL Injection
The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete_array’ parameter in versions up to, and including, 3.0.229 due to insufficient escaping on the user supplied parameter and lack…
[*, 3.0.330)
3.0.330
21/08/2015
Gallery Bank – WordPress Photo Gallery <= 3.0.101 – SQL Injection
The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show_albums’ attribute in versions up to, and including, 3.0.101 due to insufficient escaping on the user supplied parameter and lack…
*-3.0.101
3.0.102
21/02/2015
Gallery Bank – WordPress Photo Gallery Plugin < 3.0.61 – Arbitrary File Upload
The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php in versions before 3.0.61. This makes it possible for attackers to upload arbitrary…
[*, 3.0.61)
3.0.61
25/11/2014
Gallery Bank – WordPress Photo Gallery Plugin < 3.0.70 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70 for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.
[*, 3.0.70)
3.0.70
18/10/2014
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[*, 3.0.229)
3.0.229
01/08/2014
Gallery Bank – WordPress Photo Gallery Plugin < 2.0.20 – Reflected Cross-Site Scripting
The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via the ‘album_id’ parameter in edit_album.php and the 'recordsArray' parameter in the album_gallery_bank_class.php file in versions before 2.0.20 due to insufficient…
[*, 2.0.20)
2.0.20
28/10/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.