Extension WordPress
Vulnérabilités Responsive Lightbox & Gallery
Cette page rassemble les failles publiées pour Responsive Lightbox & Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Responsive Lightbox & Gallery
17 fiches
Responsive Lightbox & Gallery <= 2.7.6 – Unauthenticated Stored Cross-Site Scripting
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.7.6
2.7.7
24/06/2026
Responsive Lightbox & Gallery <= 2.7.1 – Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host…
*-2.7.1
2.7.2
24/02/2026
Responsive Lightbox & Gallery < 2.6.1 – Unauthenticated Stored Cross-Site Scripting
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
[*, 2.6.1)
2.6.1
03/02/2026
Responsive Lightbox & Gallery <= 2.5.3 – Authenticated (Author+) Server-Side Request Forgery
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image…
*-2.5.3
2.5.4
18/11/2025
Responsive Lightbox & Gallery <= 2.5.2 – Unauthenticated Stored Cross-Site Scripting
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.5.2
2.5.3
15/09/2025
Responsive Lightbox & Gallery <= 2.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SwipeBox in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.5.1
2.5.2
06/06/2025
Responsive Lightbox & Gallery <= 2.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.5.0
2.5.1
24/04/2025
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js JavaScript library (versions 1.7.13 to 1.7.14) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.4.7
2.4.8
04/03/2025
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.4.8
2.4.9
03/12/2024
Responsive Lightbox <= 2.4.8 – Authenticated (Author+) Stored Cross-Site Scripting
The Responsive Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…
*-2.4.8
2.4.9
15/10/2024
Responsive Lightbox <= 2.4.7 – Missing Authorization
The Responsive Lightbox plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_builder() function in versions up to, and including, 2.4.7. This makes it possible for unauthenticated attackers to…
*-2.4.7
2.4.8
26/08/2024
Responsive Lightbox & Gallery <= 2.4.7 – Authenticated (Author+) Stored Cross-Site Scripting via File Upload
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint.…
*-2.4.7
2.4.8
21/08/2024
Responsive Lightbox <= 2.4.6 – Missing Authorization via Information Disclosure
The Responsive Lightbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the gallery_attributes() function in versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with contributor-level access…
*-2.4.6
2.4.7
05/04/2024
Responsive Lightbox <= 2.4.5 – Authenticated (Author+) Stored Cross-Site Scripting via name
The Responsive Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-2.4.5
2.4.6
29/11/2023
Responsive Lightbox & Gallery <= 2.4.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sanitize_field’ function in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping on text fields. This makes…
*-2.4.1
2.4.2
04/11/2022
Responsive Lightbox & Gallery <= 1.7.1 – Cross-Site Scripting
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
*-1.7.1
1.7.2
01/12/2016
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[*, 1.4.12)
1.4.12
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.