plugin

Gallery Bank Vulnerabilities

30 known security issues reported for the Gallery Bank WordPress plugin. Most recent disclosed Jul 18, 2023.

1 critical 2 high 6 medium

Running Gallery Bank on your site? Check whether your installed version is affected.

Scan your site free

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.0.18
Fixed in:
4.0.19
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 - Stored Cross-Site Scripting via Media Upload

medium

The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media upload module in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.

CVSS:
6.4
Affected:
up to 4.0.50
Fix:
No patched version reported
Disclosed:
Jun 9, 2022

Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 - Stored Cross-Site Scripting via Gallery Description

medium

The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Gallery Description in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.

CVSS:
6.4
Affected:
up to 4.0.50
Fix:
No patched version reported
Disclosed:
Jun 9, 2022

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed)

unknown

The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media upload module in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.

Affected:
up to 4.0.50
Fix:
No patched version reported
Disclosed:
Jun 9, 2022

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed)

unknown

The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Gallery Description in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.

Affected:
up to 4.0.50
Fix:
No patched version reported
Disclosed:
Jun 9, 2022

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (closed)

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Gallery Description discovered by Vishnupriya Ilango (Fortinet's FortiGuard Labs) in WordPress Gallery Bank plugin (versions <= 4.0.50). Deactivate and delete. This plugin has been closed as of December 9, 2021 and is not available for download. Reason:...

Affected:
up to 4.0.50
Fixed in:
4.0.50
Disclosed:
Jun 9, 2022

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (closed)

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Media Upload Module discovered by Vishnupriya Ilango (Fortinet FortiGuard Labs) in WordPress Gallery Bank plugin (versions <= 4.0.50). Deactivate and delete. This plugin has been closed as of December 9, 2021 and is not available for download. Reason: Se...

Affected:
up to 4.0.50
Fixed in:
4.0.50
Disclosed:
Jun 9, 2022

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.70 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.

Affected:
up to 3.0.70
Fixed in:
3.0.70
Disclosed:
Oct 6, 2017

CVE-2014-8758 on NVD →

Gallery Bank – WordPress Photo Gallery Plugin <= 3.0.229 - SQL Injection

high

The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete_array’ parameter in versions up to, and including, 3.0.229 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

CVSS:
8.8
Affected:
up to 3.0.330
Fixed in:
3.0.330
Disclosed:
Aug 21, 2015

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.330

unknown

The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete_array’ parameter in versions up to, and including, 3.0.229 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

Affected:
up to 3.0.330
Fixed in:
3.0.330
Disclosed:
Aug 21, 2015

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.229 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 3.0.229
Fixed in:
3.0.229
Disclosed:
May 14, 2015

Gallery Bank – WordPress Photo Gallery <= 3.0.101 - SQL Injection

high

The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show_albums’ attribute in versions up to, and including, 3.0.101 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...

CVSS:
8.8
Affected:
up to 3.0.101
Fixed in:
3.0.102
Disclosed:
Feb 21, 2015

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.102

unknown

The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show_albums’ attribute in versions up to, and including, 3.0.101 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...

Affected:
up to 3.0.102
Fixed in:
3.0.102
Disclosed:
Feb 21, 2015

Gallery Bank – WordPress Photo Gallery Plugin < 3.0.61 - Arbitrary File Upload

critical

The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php in versions before 3.0.61. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possi...

CVSS:
9.8
Affected:
up to 3.0.61
Fixed in:
3.0.61
Disclosed:
Nov 25, 2014

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.61

unknown

The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php in versions before 3.0.61. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possi...

Affected:
up to 3.0.61
Fixed in:
3.0.61
Disclosed:
Nov 25, 2014

Gallery Bank – WordPress Photo Gallery Plugin < 3.0.70 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70 for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 3.0.70
Fixed in:
3.0.70
Disclosed:
Oct 18, 2014

CVE-2014-8758 on NVD →

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS:
6.1
Affected:
up to 3.0.229
Fixed in:
3.0.229
Disclosed:
Aug 1, 2014

CVE-2013-6837 on NVD →

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.229

unknown

[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Affected:
up to 3.0.229
Fixed in:
3.0.229
Disclosed:
Dec 19, 2013

CVE-2013-6837 on NVD →

Gallery Bank – WordPress Photo Gallery Plugin < 2.0.20 - Reflected Cross-Site Scripting

medium

The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via the ‘album_id’ parameter in edit_album.php and the 'recordsArray' parameter in the album_gallery_bank_class.php file in versions before 2.0.20 due to insufficient input sanitization and output es...

CVSS:
6.1
Affected:
up to 2.0.20
Fixed in:
2.0.20
Disclosed:
Oct 28, 2013

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20

unknown

The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via the ‘album_id’ parameter in edit_album.php and the 'recordsArray' parameter in the album_gallery_bank_class.php file in versions before 2.0.20 due to insufficient input sanitization and output es...

Affected:
up to 2.0.20
Fixed in:
2.0.20
Disclosed:
Oct 28, 2013

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.61

unknown

The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by a Shell Upload security vulnerability.

Affected:
up to 3.0.61
Fixed in:
3.0.61

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20

unknown

The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by an album-gallery-bank-class.php recordsArray Parameter Reflected XSS security vulnerability.

Affected:
up to 2.0.20
Fixed in:
2.0.20

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20

unknown

The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by an edit-album.php album_id Parameter Reflected XSS security vulnerability.

Affected:
up to 2.0.20
Fixed in:
2.0.20

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20

unknown

The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by a Multiple Unspecified Issues security vulnerability.

Affected:
up to 2.0.20
Fixed in:
2.0.20

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.102

unknown

The Gallery Bank &ndash; Responsive Photo Gallery plugin exposes a Short Code named &lsquo;gallery_bank&rsquo;, in order to allow site publishers to insert galleries into pages / posts. This Short Code is vulnerable to a UNION based SQL Injection. This is possible by manipulating the field &lsquo;show_albums&rsquo; whe...

Affected:
up to 3.0.102
Fixed in:
3.0.102

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.330

unknown

The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.

Affected:
up to 3.0.330
Fixed in:
3.0.330

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed + closed)

unknown

The plugin does not sanitise and escape the Image Title field via the Media Upload module, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks

Affected:
up to 4.0.50
Fix:
No patched version reported

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed + closed)

unknown

The plugin does not sanitise and escape the Gallery Description field, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks

Affected:
up to 4.0.50
Fix:
No patched version reported

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.229

unknown

The jQuery prettyPhoto library bundled with many plugins was found to be vulnerable to DOM Cross-Site Scripting (XSS).

Affected:
up to 3.0.229
Fixed in:
3.0.229

Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 4.0.19

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 4.0.19
Fixed in:
4.0.19

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database