Extension WordPress

Vulnérabilités Gallery Bank – WordPress Photo Gallery Plugin

Cette page rassemble les failles publiées pour Gallery Bank – WordPress Photo Gallery Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
1Critiques
7Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Gallery Bank – WordPress Photo Gallery Plugin

9 fiches

CVE-2023-33999 Moyenne · 6,1
Gallery Bank – WordPress Photo Gallery Plugin

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-4.0.18

Correctif

4.0.19

Publication

18/07/2023

Vulnérabilité Moyenne · 6,4
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 – Stored Cross-Site Scripting via Gallery Description

The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Gallery Description in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.

Versions affectées

*-4.0.50

Correctif

Non indiqué

Publication

09/06/2022

Vulnérabilité Moyenne · 6,4
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 – Stored Cross-Site Scripting via Media Upload

The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media upload module in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.

Versions affectées

*-4.0.50

Correctif

Non indiqué

Publication

09/06/2022

Vulnérabilité Élevée · 8,8
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery Plugin <= 3.0.229 – SQL Injection

The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete_array’ parameter in versions up to, and including, 3.0.229 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

[*, 3.0.330)

Correctif

3.0.330

Publication

21/08/2015

Vulnérabilité Élevée · 8,8
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery <= 3.0.101 – SQL Injection

The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show_albums’ attribute in versions up to, and including, 3.0.101 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

*-3.0.101

Correctif

3.0.102

Publication

21/02/2015

Vulnérabilité Critique · 9,8
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery Plugin < 3.0.61 – Arbitrary File Upload

The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php in versions before 3.0.61. This makes it possible for attackers to upload arbitrary…

Versions affectées

[*, 3.0.61)

Correctif

3.0.61

Publication

25/11/2014

CVE-2014-8758 Moyenne · 6,1
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery Plugin < 3.0.70 – Reflected Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70 for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.

Versions affectées

[*, 3.0.70)

Correctif

3.0.70

Publication

18/10/2014

CVE-2013-6837 Moyenne · 6,1
Gallery Bank – WordPress Photo Gallery Plugin

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Versions affectées

[*, 3.0.229)

Correctif

3.0.229

Publication

01/08/2014

Vulnérabilité Moyenne · 6,1
Gallery Bank – WordPress Photo Gallery Plugin

Gallery Bank – WordPress Photo Gallery Plugin < 2.0.20 – Reflected Cross-Site Scripting

The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via the ‘album_id’ parameter in edit_album.php and the 'recordsArray' parameter in the album_gallery_bank_class.php file in versions before 2.0.20 due to insufficient…

Versions affectées

[*, 2.0.20)

Correctif

2.0.20

Publication

28/10/2013

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités