Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Responsive Lightbox MEDIUM 5.4
CVE-2025-5093

The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before o…

Fix: 2.5.2+
Fix from $1,600 2025-06-27
Responsive Lightbox MEDIUM 6.8
CVE-2025-3742

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a …

Fix: 2.5.1+
Fix from $1,600 2025-05-15
Responsive Lightbox CRITICAL 9.8
CVE-2024-43924

Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

Fix: 2.4.8+
Fix from $2,300 2024-10-23
Responsive Lightbox MEDIUM 5.4
CVE-2024-6870

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and inclu…

Fix: 2.4.8+
Fix from $1,600 2024-08-22
Responsive Lightbox \& Gallery HIGH 8.8
CVE-2024-31252

Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.

Fix: 2.4.7+
Fix from $1,950 2024-06-09
Responsive Lightbox MEDIUM 5.4
CVE-2023-49174

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox & Gallery allows S…

Fix: 2.4.6+
Fix from $1,600 2023-12-15
Download Attachments MEDIUM 5.4
CVE-2023-0076

The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a p…

Fix: 1.2.24+
Fix from $1,600 2023-03-06
Responsive Lightbox MEDIUM 6.1
CVE-2017-2243

Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspec…

Fix: after 1.7.1
Fix from $1,600 2017-07-07