Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Photo Gallery CRITICAL 9.8
CVE-2019-14313

A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability wou…

Fix: 1.5.31+
Fix from $2,300 2019-07-30
Form Maker CRITICAL 9.8
CVE-2019-10866EPSS 6%

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-m…

Fix: 1.13.3+
Fix from $2,300 2019-05-23
Form Maker HIGH 8.8
CVE-2019-11590

The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclu…

Fix: 1.13.5+
Fix from $1,950 2019-04-29
Photo Gallery MEDIUM 5.4
CVE-2015-2324

Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users…

Fix: 1.2.13+
Fix from $1,600 2018-02-19
Photo Gallery HIGH 8.8
CVE-2014-9312EPSS 45%

Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.

No fix yet
Fix from $1,950 2017-08-28
Photo Gallery HIGH 7.2
CVE-2017-12977

The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_e…

Fix: after 1.3.50
Fix from $1,950 2017-08-21
Photo Gallery MEDIUM 6.5
CVE-2015-1393

SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL comman…

Fix: after 1.2.9
Fix from $1,600 2015-02-02
Photo Gallery HIGH 7.5
CVE-2015-1055

SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_b…

No fix yet
Fix from $1,950 2015-01-16