Enviragallery

Envira Gallery

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 01.11.2024 15:15:48
  • Zuletzt bearbeitet 13.11.2024 01:23:41

Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Photo Gallery: from n/a through 1.8.14.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 11.09.2024 06:15:01
  • Zuletzt bearbeitet 25.09.2024 19:37:28

The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.

  • EPSS 0.13%
  • Veröffentlicht 11.01.2024 09:15:51
  • Zuletzt bearbeitet 21.11.2024 08:44:27

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 31.10.2022 16:15:10
  • Zuletzt bearbeitet 07.05.2025 14:15:30

The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Exploit
  • EPSS 0.16%
  • Veröffentlicht 18.03.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:52:24

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to priv...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 15.01.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:38

A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php request with the meta[title] parameter.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 15.01.2021 07:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:38

A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php request with the post_title parameter.

  • EPSS 0.48%
  • Veröffentlicht 25.02.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:40:25

A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by othe...