Extension WordPress
Vulnérabilités Gallery Images Ape
Cette page rassemble les failles publiées pour Gallery Images Ape, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gallery Images Ape
5 fiches
Gallery Images Ape <= 2.2.8 – Reflected Cross-Site Scripting
The Gallery Images Ape plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.2.8
Non indiqué
03/01/2025
Gallery Images Ape <= 2.2.8 – Authenticated (Contributor+) Cross-Site Scripting
The Gallery Images Ape plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…
*-2.2.8
Non indiqué
31/10/2022
Gallery Images Ape <= 2.2.8 – Missing Authorization
The Gallery Images Ape plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when modifying galleries in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.2.8
Non indiqué
31/10/2022
Gallery Images Ape <= 2.0.6 – Authenticated Plugin Deactivation
The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin on the site, including plugins necessary…
[*, 2.0.7)
2.0.7
30/12/2019
Gallery Images Ape <= 1.6.14 – Stored Cross-Site Scripting
The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function.
*-1.6.14
2.0.0
10/01/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.