VYPR

Wp Youtube Gallery

by WordPress

Source repositories

CVEs (3)

  • CVE-2024-12590MedJan 7, 2025
    risk 0.35cvss 6.4epss 0.00

    The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2014-4960Jul 21, 2014
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

  • CVE-2022-4783Feb 13, 2023
    risk 0.00cvss epss 0.00

    The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…