Extension WordPress
Vulnérabilités Pixabay Images
Cette page rassemble les failles publiées pour Pixabay Images, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Pixabay Images
5 fiches
Pixabay Images <= 3.4 – Authenticated (Author+) Arbitrary File Upload
The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with…
*-3.4
Non indiqué
17/06/2025
Pixabay Images <= 2.3 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.
[*, 2.4)
2.4
19/01/2015
Pixabay Images <= 2.3 – Arbitrary File Upload
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.
*-2.3
2.4
19/01/2015
Pixabay Images <= 2.0 – Authentication Bypass to Arbitrary File Upload
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.
*-2.0
2.4
19/01/2015
Pixabay Images <= 2.3 – Directory Traversal
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.
*-2.3
2.4
19/01/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.