Extension WordPress
Vulnérabilités ReFlex Gallery » WordPress Photo Gallery
Cette page rassemble les failles publiées pour ReFlex Gallery » WordPress Photo Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ReFlex Gallery » WordPress Photo Gallery
4 fiches
ReFlex Gallery < 1.4.3 – Cross-Site Scripting
The reflex-gallery plugin before 1.4.3 for WordPress has XSS via Edit Content URL field.
[*, 1.4.3)
1.4.3
06/08/2021
ReFlex Gallery » WordPress Photo Gallery < 3.1.4 – Arbitrary File Upload
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request…
[*, 3.1.4)
3.1.4
16/03/2015
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[*, 3.1.5)
3.1.5
01/08/2014
ReFlex Gallery » WordPress Photo Gallery < 3.1.4 – Arbitrary File Upload
The ReFlex Gallery » WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.php file in versions up to, and including, 3.1.3. This makes it possible for unauthenticated…
[*, 3.1.4)
3.1.4
03/01/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.