Extension WordPress

Vulnérabilités SimpLy Gallery

Cette page rassemble les failles publiées pour SimpLy Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de SimpLy Gallery

12 fiches

CVE-2026-5743 Moyenne · 6,4
SimpLy Gallery

Mixed Media Gallery Blocks <= 3.3.3.1 – Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2. This is due to insufficient input sanitization and output escaping on the…

Versions affectées

*-3.3.3.1

Correctif

3.3.3.2

Publication

10/07/2026

CVE-2024-13362 Moyenne · 6,1
SimpLy Gallery

Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-3.2.4.4

Correctif

3.2.4.5

Publication

30/04/2026

CVE-2025-14288 Moyenne · 4,3
SimpLy Gallery

Gallery Blocks with Lightbox <= 3.3.0 – Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to unauthorized modification of plugin settings in all versions up to, and including, 3.3.0.…

Versions affectées

*-3.3.0

Correctif

3.3.1

Publication

12/12/2025

CVE-2025-63052 Moyenne · 6,4
SimpLy Gallery

SimpLy Gallery <= 3.3.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The SimpLy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-3.3.2.1

Correctif

3.3.2.2

Publication

26/10/2025

CVE-2025-32176 Moyenne · 6,4
SimpLy Gallery

Gallery Blocks with Lightbox <= 3.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Gallery Blocks with Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-3.2.5

Correctif

3.2.6

Publication

04/04/2025

CVE-2024-10034 Moyenne · 5,5
SimpLy Gallery

Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.4.2 – Authenticated (Editor+) Stored Cross-Site Scripting

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery link text parameter in all versions up…

Versions affectées

*-3.2.4.2

Correctif

3.2.4.3

Publication

21/11/2024

CVE-2024-5424 Moyenne · 6,4
SimpLy Gallery

Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘galleryID’ and 'className' parameters in all versions up…

Versions affectées

*-3.2.1

Correctif

3.2.2

Publication

27/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités