Photogallery
by WordPress
Source repositories
CVEs (44)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65519 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||
| CVE-2015-1393 | 0.00 | — | 0.02 | Feb 2, 2015 | SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php. | |||
| CVE-2015-1055 | 0.00 | — | 0.02 | Jan 16, 2015 | SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php. | |||
| CVE-2014-6315 | 0.00 | — | 0.02 | Oct 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to… |
- risk 0.00cvss 6.5epss 0.00
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
- CVE-2015-1393Feb 2, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
- CVE-2015-1055Jan 16, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
- CVE-2014-6315Oct 10, 2014risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to…
Page 3 of 3