CVE-2026-2497
- EPSS 0.32%
- Veröffentlicht 16.08.2026 06:38:08
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insufficient escaping on the user supplied parameter an...
CVE-2026-57642
- EPSS 0.21%
- Veröffentlicht 26.06.2026 14:53:16
- Zuletzt bearbeitet 29.06.2026 16:16:44
Contributor SQL Injection in Gallery <= 4.7.8 versions.
CVE-2023-0764
- EPSS 0.44%
- Veröffentlicht 17.04.2023 13:15:37
- Zuletzt bearbeitet 06.02.2025 17:15:14
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.
CVE-2023-0765
- EPSS 0.87%
- Veröffentlicht 17.04.2023 13:15:37
- Zuletzt bearbeitet 05.03.2025 19:15:27
The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin...
CVE-2017-2171
- EPSS 0.89%
- Veröffentlicht 22.05.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prio...