Extension WordPress
Vulnérabilités Photo Gallery by Ays – Responsive Image Gallery
Cette page rassemble les failles publiées pour Photo Gallery by Ays – Responsive Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Photo Gallery by Ays – Responsive Image Gallery
10 fiches
Photo Gallery by Ays <= 6.4.8 – Cross-Site Request Forgery to Bulk Actions
The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function.…
*-6.4.8
6.4.9
01/12/2025
Photo Gallery by Ays <= 6.3.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Photo Gallery by Ays plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-6.3.8
6.3.9
22/09/2025
Photo Gallery by Ays <= 5.7.0 – Authenticated (Administrator+) HTML Injection
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.7.0 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 5.7.1)
5.7.1
28/06/2024
Photo Gallery by Ays <= 5.5.2 – Reflected Cross-Site Scripting
The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-5.5.2
5.5.3
25/03/2024
Photo Gallery by Ays <= 5.2.6 – Cross-Site Request Forgery
The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing nonce validation in the /admin/partials/gallery-photo-gallery-admin-display.php file. This makes it possible for unauthenticated…
*-5.2.6
5.2.7
07/08/2023
Photo Gallery by Ays <= 5.1.6 – Reflected Cross-Site Scripting
The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-5.1.6
5.1.7
16/05/2023
Photo Gallery by Ays <= 5.1.3 – Reflected Cross-Site Scripting via ays_gpg_settings_tab
The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ays_gpg_settings_tab’ parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-5.1.3
5.1.4
03/05/2023
Photo Gallery by Ays – Responsive Image Gallery <= 4.4.3 – Reflected Cross-Site Scripting
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes…
*-4.4.3
4.4.4
29/06/2021
Photo Gallery by Ays – Responsive Image Gallery <= 4.4.3 – Authenticated Blind SQL Injections
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results()…
[*, 4.4.4)
4.4.4
29/06/2021
Photo Gallery by Ays – Responsive Image Gallery < 1.0.1 – SQL Injection
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to 1.0.1 due to insufficient escaping on the user supplied parameter and lack of…
[*, 1.0.1)
1.0.1
11/07/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.