Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.2
CVE-2022-2633
- EPSS 27.19%
- Veröffentlicht 06.09.2022 18:15:14
- Zuletzt bearbeitet 21.11.2024 07:01:24
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possib...
7.2
CVE-2021-24970
- EPSS 5.9%
- Veröffentlicht 13.12.2021 11:15:09
- Zuletzt bearbeitet 21.11.2024 05:54:06
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue