Extension WordPress

Vulnérabilités Slideshow Gallery LITE

Cette page rassemble les failles publiées pour Slideshow Gallery LITE, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
1Critiques
19Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Slideshow Gallery LITE

19 fiches

CVE-2026-2021 Moyenne · 6,4
Slideshow Gallery LITE

Slideshow Gallery LITE <= 1.8.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied…

Versions affectées

*-1.8.5

Correctif

1.8.6

Publication

17/06/2026

CVE-2024-47376 Moyenne · 4,4
Slideshow Gallery LITE

Slideshow Gallery <= 1.8.3 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Slideshow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…

Versions affectées

*-1.8.3

Correctif

1.8.4

Publication

30/09/2024

Vulnérabilité Moyenne · 6,1
Slideshow Gallery LITE

Slideshow Gallery <= 1.5.3.2 – Reflected Cross-Site Scripting

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ parameter in versions up to, and including, 1.5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 1.5.3.4)

Correctif

1.5.3.4

Publication

20/08/2015

Vulnérabilité Élevée · 8,8
Slideshow Gallery LITE

Slideshow Gallery <= 1.5.3.1 – Cross-Site Request Forgery to Arbitrary File Upload

The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.3.1. This is due to missing nonce validation on the save slideshow functionality. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.5.3.1

Correctif

1.5.3.2

Publication

20/08/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités