Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] <= 6.1.2 (unfixed + closed)
unknown
[en] The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 6.1.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2022
CVE-2021-24903 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 6.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 6.1.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 12, 2021
CVE-2021-24903 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 4.25 (closed)
unknown
[en] The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-album-gallery/skins/banner_widget_default/gallery.php.
- Affected:
- up to 4.25
- Fixed in:
- 4.25
- Disclosed:
- Oct 18, 2017
CVE-2014-8491 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.12 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- Jul 27, 2016
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.57 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.57
- Fixed in:
- 1.57
- Disclosed:
- May 15, 2015
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.76 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability in wp-admin/admin.php skin parameter.
Update the plugin.
- Affected:
- up to 1.76
- Fixed in:
- 1.76
- Disclosed:
- May 15, 2015
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.0.1 (closed)
unknown
This plugin is prone to:
arbitrary file overwrite vulnerability in "admin/skin_options.php", "lib/constructor.php";
directory structure disclosure vulnerability in "admin/ajax.php";
arbitrary file disclosure vulnerability in "admin/news.php";
arbitrary directory deletion vulnerability in "admin/skins.php";
SQL inj...
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- May 15, 2015
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.17 (closed)
unknown
This plugin is prone to cross site scripting and SQL injection vulnerabiliites.
Update the plugin.
- Affected:
- up to 2.17
- Fixed in:
- 2.17
- Disclosed:
- May 15, 2015
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.56 (closed)
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Vulnerable parameter "gid".
Update the plugin.
- Affected:
- up to 2.56
- Fixed in:
- 2.56
- Disclosed:
- May 15, 2015
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 4.25 - Sensitive Data Exposure
medium
The Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1) flagallery-skins/banner_widget_default/gallery.php or (2) flash-album-gallery/skins/banner_widget_default/gallery.php.
- CVSS:
- 5.3
- Affected:
- up to 4.25
- Fixed in:
- 4.25
- Disclosed:
- Oct 30, 2014
CVE-2014-8491 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.57 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
- Affected:
- up to 1.57
- Fixed in:
- 1.57
- Disclosed:
- Oct 1, 2014
CVE-2011-4624 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 0.59 - SQL Injection
critical
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'pid' parameter in the 'lib/hitcounter.php' in versions up to, and including, 0.59 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on...
- CVSS:
- 9.8
- Affected:
- up to 0.59
- Fixed in:
- 0.60
- Disclosed:
- Aug 1, 2014
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.72 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
- CVSS:
- 6.1
- Affected:
- up to 2.71
- Fixed in:
- 2.72
- Disclosed:
- Aug 1, 2014
CVE-2013-3261 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 0.60
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'pid' parameter in the 'lib/hitcounter.php' in versions up to, and including, 0.59 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on...
- Affected:
- up to 0.60
- Fixed in:
- 0.60
- Disclosed:
- Aug 1, 2014
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.12
unknown
[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- Jul 19, 2013
CVE-2012-3414 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.72 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
- Affected:
- up to 2.72
- Fixed in:
- 2.72
- Disclosed:
- Jun 1, 2013
CVE-2013-3261 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.55 - SQL Injection
high
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ' $id' variable in the lib/shortcodes.php file in versions up to, and including, 2.55 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...
- CVSS:
- 7.2
- Affected:
- up to 2.55
- Fixed in:
- 2.56
- Disclosed:
- Mar 25, 2013
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.56
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ' $id' variable in the lib/shortcodes.php file in versions up to, and including, 2.55 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...
- Affected:
- up to 2.56
- Fixed in:
- 2.56
- Disclosed:
- Mar 25, 2013
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 - SQL Injection
high
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the lib/shortcodes.php file in versions up to, and including, 2.00 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...
- CVSS:
- 8.8
- Affected:
- up to 2.00
- Fixed in:
- 2.10
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 - SQL Injection
high
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ‘form’ parameter in the admin/ajax.php file in versions up to, and including, 2.00 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...
- CVSS:
- 7.2
- Affected:
- up to 2.10
- Fixed in:
- 2.10
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.53 - SQL Injection
high
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'description' parameter in the admin/manage.php file in versions up to 2.53 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...
- CVSS:
- 7.2
- Affected:
- up to 2.53
- Fixed in:
- 2.53
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 3.1.0 - Arbitrary File Deletion
high
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 3.0.1 via the 'delete' parameter. This makes it possible for authenticated attackers to delete the contents of arbitrary files on the...
- CVSS:
- 7.2
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 2.53 - Sensitive Information Disclosure
medium
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.52 via the 'dir' parameter in the admin/ajax.php file, the 'want2read' parameter in the admin/news.php file, and the 'f' parameter in the facebook.php...
- CVSS:
- 4.9
- Affected:
- up to 2.53
- Fixed in:
- 2.53
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 2.00 - Arbitrary File Modification
medium
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file modification in versions up to, and including, 2.00. This is due to unsanitized user input on the 'settingsXML', and 'mainXML' parameters in the admin/skin_options.php file, and the 'skin_name' an...
- CVSS:
- 4.9
- Affected:
- up to 2.00
- Fixed in:
- 2.10
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 3.1.0
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 3.0.1 via the 'delete' parameter. This makes it possible for authenticated attackers to delete the contents of arbitrary files on the...
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.53
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic SQL Injection via the 'description' parameter in the admin/manage.php file in versions up to 2.53 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...
- Affected:
- up to 2.53
- Fixed in:
- 2.53
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.10
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the lib/shortcodes.php file in versions up to, and including, 2.00 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...
- Affected:
- up to 2.10
- Fixed in:
- 2.10
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.10
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary file modification in versions up to, and including, 2.00. This is due to unsanitized user input on the 'settingsXML', and 'mainXML' parameters in the admin/skin_options.php file, and the 'skin_name' an...
- Affected:
- up to 2.10
- Fixed in:
- 2.10
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.10
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injection via the ‘form’ parameter in the admin/ajax.php file in versions up to, and including, 2.00 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...
- Affected:
- up to 2.10
- Fixed in:
- 2.10
- Disclosed:
- Dec 24, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.53
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.52 via the 'dir' parameter in the admin/ajax.php file, the 'want2read' parameter in the admin/news.php file, and the 'f' parameter in the facebook.php...
- Affected:
- up to 2.53
- Fixed in:
- 2.53
- Disclosed:
- Dec 24, 2012
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio <= 1.72 - Reflected Cross-Site Scripting
medium
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'skin' parameter in versions up to, and including, 1.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 1.72
- Fixed in:
- 1.73
- Disclosed:
- May 15, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.73
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'skin' parameter in versions up to, and including, 1.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 1.73
- Fixed in:
- 1.73
- Disclosed:
- May 15, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.72 (closed)
unknown
WordPress GRAND Flash Album Gallery plugin's "admin.php" is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based au...
- Affected:
- up to 1.72
- Fixed in:
- 1.72
- Disclosed:
- May 15, 2012
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.1 (closed)
unknown
WordPress Flash Album Gallery plugin's "flagshow.php" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-b...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Dec 13, 2011
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio < 1.57 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.57
- Fixed in:
- 1.57
- Disclosed:
- Nov 30, 2011
CVE-2011-4624 on NVD →
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 0.56 (closed)
unknown
There are several vulnerabilities in this WordPress GRAND Flash Album Gallery plugin.
First vulnerability is SQL injection that exists because of failure in the "/wp-content/plugins/flash-album-gallery/lib/hitcounter.php" script to properly sanitize user-supplied input in "pid" variable. It allows an attacker to...
- Affected:
- up to 0.56
- Fixed in:
- 0.56
- Disclosed:
- Mar 8, 2011
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 0.60
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin was affected by a lib/hitcounter.php pid Parameter SQL Injection security vulnerability.
- Affected:
- up to 0.60
- Fixed in:
- 0.60
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.10
unknown
The plugin was affected by Multiple Vulnerabilities security issues, such as file disclosure, file overwrite, directory traversal, and remote SQL injection
- Affected:
- up to 2.10
- Fixed in:
- 2.10
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.76
unknown
The plugin did not sanitise or escape the skin parameter before putting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.76
- Fixed in:
- 1.76
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 1.67
unknown
The plugin did not sanitise or escape the I parameter in the facebook.php file, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.67
- Fixed in:
- 1.67
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.56
unknown
- Affected:
- up to 2.56
- Fixed in:
- 2.56
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] <= 0.55 (unfixed)
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin was affected by an admin/news.php want2Read Parameter Traversal Arbitrary File Access security vulnerability.
- Affected:
- up to 0.55
- Fix:
- No patched version reported
Album and Image Gallery with Lightbox – Flagallery Photo Portfolio [flash-album-gallery] < 2.17
unknown
The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 2.17
- Fixed in:
- 2.17