VYPR
Vendor

Elkagroup

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2016-11018CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

  • CVE-2024-35721MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through 1.4.5.

  • CVE-2009-4569Jan 5, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.

  • CVE-2009-2930Aug 21, 2009
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.

  • CVE-2009-1446Apr 27, 2009
    risk 0.03cvss epss 0.03

    Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some…

  • CVE-2008-5037Nov 12, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2007-3461Jun 27, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.