Extension WordPress
Vulnérabilités Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery
Cette page rassemble les failles publiées pour Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery
5 fiches
YouTube Gallery and Vimeo Gallery Plugin <= 2.4.2 – Authenticated (Administrator+) SQL Injection
The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied…
*-2.4.2
2.4.3
05/12/2024
Video Gallery <= 2.4.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes…
*-2.4.1
2.4.2
05/12/2024
Video Gallery – YouTube Gallery <= 2.1.4 – Authenticated (Administrator+) SQL Injection
The Video Gallery – YouTube Gallery plugin for WordPress is vulnerable to SQL Injection via 's' and 'orderby' in versions up to, and including, 2.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-2.1.4
2.1.5
03/10/2023
Video Gallery – YouTube Gallery <= 1.7.6 – Authenticated (Admin+) Stored Cross Site Scripting
The Video Gallery – YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.7.6
1.7.7
20/02/2023
Video Gallery – YouTube Gallery <= 1.7.6 – Missing Authorization
The Video Gallery – YouTube Gallery plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 1.7.6 via the 'Total-Soft-Gallery-Video-Ajax.php' file due to a lack of capability and nonce checks on multiple functions. This…
*-1.7.6
1.7.7
20/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.