Photogallery
by WordPress
Source repositories
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13685 | Med | 0.21 | 4.3 | 0.00 | Dec 2, 2025 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for… | ||
| CVE-2006-6937 | 0.03 | — | 0.01 | Jan 17, 2007 | SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter. | |||
| CVE-2026-65519 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||
| CVE-2015-1393 | 0.00 | — | 0.02 | Feb 2, 2015 | SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php. | |||
| CVE-2015-1055 | 0.00 | — | 0.02 | Jan 16, 2015 | SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php. | |||
| CVE-2014-6315 | 0.00 | — | 0.02 | Oct 10, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to… |
- risk 0.21cvss 4.3epss 0.00
The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for…
- CVE-2006-6937Jan 17, 2007risk 0.03cvss —epss 0.01
SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.
- risk 0.00cvss 6.5epss 0.00
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
- CVE-2015-1393Feb 2, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
- CVE-2015-1055Jan 16, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
- CVE-2014-6315Oct 10, 2014risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to…
Page 3 of 3