CVE-2025-57947
- EPSS 0.05%
- Veröffentlicht 22.09.2025 18:24:54
- Zuletzt bearbeitet 22.09.2025 21:22:33
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays allows DOM-Based XSS. This issue affects Photo Gallery by Ays: from n/a through 6.3.6.
CVE-2024-37442
- EPSS 0.14%
- Veröffentlicht 09.07.2024 11:15:14
- Zuletzt bearbeitet 21.11.2024 09:23:51
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.
CVE-2023-39917
- EPSS 0.15%
- Veröffentlicht 03.10.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:16:02
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions.
CVE-2023-32107
- EPSS 0.08%
- Veröffentlicht 18.08.2023 14:15:23
- Zuletzt bearbeitet 21.11.2024 08:02:43
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions.
CVE-2023-2568
- EPSS 0.13%
- Veröffentlicht 12.06.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:58:50
The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2021-24462
- EPSS 0.53%
- Veröffentlicht 02.08.2021 11:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:07
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the ge...
CVE-2016-10921
- EPSS 0.55%
- Veröffentlicht 22.08.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 02:45:04
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.