Ays-pro

Photo Gallery

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 22.09.2025 18:24:54
  • Zuletzt bearbeitet 22.09.2025 21:22:33

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays allows DOM-Based XSS. This issue affects Photo Gallery by Ays: from n/a through 6.3.6.

  • EPSS 0.14%
  • Veröffentlicht 09.07.2024 11:15:14
  • Zuletzt bearbeitet 21.11.2024 09:23:51

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.

  • EPSS 0.15%
  • Veröffentlicht 03.10.2023 12:15:10
  • Zuletzt bearbeitet 21.11.2024 08:16:02

Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions.

  • EPSS 0.08%
  • Veröffentlicht 18.08.2023 14:15:23
  • Zuletzt bearbeitet 21.11.2024 08:02:43

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 12.06.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:58:50

The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Exploit
  • EPSS 0.53%
  • Veröffentlicht 02.08.2021 11:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:07

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the ge...

  • EPSS 0.55%
  • Veröffentlicht 22.08.2019 13:15:12
  • Zuletzt bearbeitet 21.11.2024 02:45:04

The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.