Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-14313 A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability wou… Photo Gallery 1.5.31+ Fix from $2,3002019-07-30 CRITICAL 9.8 CVE-2019-10866EPSS 6% In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-m… Form Maker 1.13.3+ Fix from $2,3002019-05-23 HIGH 8.8 CVE-2019-11590 The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclu… Form Maker 1.13.5+ Fix from $1,9502019-04-29 MEDIUM 5.4 CVE-2015-2324 Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users… Photo Gallery 1.2.13+ Fix from $1,6002018-02-19 HIGH 8.8 CVE-2014-9312EPSS 45% Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. Photo Gallery No fix yet Fix from $1,9502017-08-28 HIGH 7.2 CVE-2017-12977 The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_e… Photo Gallery after 1.3.50 Fix from $1,9502017-08-21 MEDIUM 6.5 CVE-2015-1393 SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL comman… Photo Gallery after 1.2.9 Fix from $1,6002015-02-02 HIGH 7.5 CVE-2015-1055 SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_b… Photo Gallery No fix yet Fix from $1,9502015-01-16