VYPR

Photogallery

by WordPress

Source repositories

CVEs (46)

  • CVE-2025-13685MedDec 2, 2025
    risk 0.21cvss 4.3epss 0.00

    The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for…

  • CVE-2006-6937Jan 17, 2007
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.

  • CVE-2026-65519MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

  • CVE-2015-1393Feb 2, 2015
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.

  • CVE-2015-1055Jan 16, 2015
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.

  • CVE-2014-6315Oct 10, 2014
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to…

Page 3 of 3