VYPR

All In One Video Gallery

by Plugins360

CVEs (4)

  • CVE-2022-2633HigSep 6, 2022
    risk 0.51cvss 7.5epss 0.27

    The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users…

  • CVE-2021-24970HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.06

    The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

  • CVE-2024-6629MedJul 24, 2024
    risk 0.35cvss 6.4epss 0.00

    The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-31248MedJun 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2.