Extension WordPress
Vulnérabilités Image Slider
Cette page rassemble les failles publiées pour Image Slider, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Image Slider
6 fiches
Image Slider <= 1.1.125 – Authenticated (Editor+) Stored Cross-Site Scripting
The Image Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.1.125 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.1.125
1.1.127
22/04/2024
Image Slider <= 1.1.121 – Cross-Site Request Forgery to Post Duplication
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible…
*-1.1.121
1.1.123
24/05/2022
Image Slider <= 1.1.119 – Subscriber+ SQL Injection
The plugin Image Slider is vulnerable to SQL Injection via the post parameter in the function ewic_duplicate_slider in versions up to, and including 1.1.119 due to insufficient sanitization before using it in an unprepared SQL query. This make…
*-1.1.119
1.1.121
24/05/2022
Image Slider <= 1.1.95 – SQL Injection
The Image Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'image-slider-widget/trunk/inc/functions/ewic-functions.php' file in the '$file' and ' $post_id' parameters in versions up to, and including, 1.1.95 due to insufficient escaping on the user supplied…
*-1.1.95
1.1.97
28/01/2018
Image Slider < 1.1.90 – Arbitrary File Deletion
The Image Slider plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.89. This is due to allowing any user to edit 'Sliders'. This makes it possible for authenticated attackers with account…
[*, 1.1.90)
1.1.90
23/12/2016
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[*, 1.1.7)
1.1.7
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.