VYPR

Photo Gallery

by Ays Pro

CVEs (6)

  • CVE-2016-10921CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.

  • CVE-2021-24462HigAug 2, 2021
    risk 0.57cvss 8.8epss 0.01

    The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls,…

  • CVE-2023-32107HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions.

  • CVE-2023-2568MedJun 12, 2023
    risk 0.40cvss 6.1epss 0.00

    The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2023-39917MedOct 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions.

  • CVE-2024-37442LowJul 9, 2024
    risk 0.25cvss 3.8epss 0.00

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.