Extension WordPress
Vulnérabilités Image Gallery – Responsive Photo Gallery
Cette page rassemble les failles publiées pour Image Gallery – Responsive Photo Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Image Gallery – Responsive Photo Gallery
7 fiches
Image Gallery – Responsive Photo Gallery < 2.0.6 – Authenticated Stored Cross-Site Scripting
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the requests to edit gallery images in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping.…
[*, 2.0.6)
2.0.6
23/11/2016
Image Gallery – Responsive Photo Gallery <= 1.9.57 – Cross-Site Request Forgery
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.57. This is due to missing or incorrect nonce validation on the editgallery() function. This makes…
*-1.9.57
1.9.58
19/05/2016
Huge-IT gallery-images <= 1.8.9 – SQL Injection
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
*-1.8.9
1.9.0
10/05/2016
Image Gallery – Responsive Photo Gallery <= 1.7.0 – Reflected Cross-Site Scripting via linkbutton
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘linkbutton’ parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it…
*-1.7.0
1.7.1
08/02/2016
Image Gallery – Responsive Photo Gallery <= 1.5.5 – Reflected Cross-Site Scripting
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order_by’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it…
[*, 1.5.6)
1.5.6
20/08/2015
Image Gallery – Responsive Photo Gallery <= 1.7.0 – Reflected Cross-Site Scripting via thumbtext
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘thumbtext' parameters in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it…
[*, 1.7.1)
1.7.1
12/03/2015
Image Gallery – Responsive Photo Gallery <= 1.0.7 – SQL Injection
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin
*-1.0.7
1.0.8
02/09/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.