Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 4.0.18
- Fixed in:
- 4.0.19
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 - Stored Cross-Site Scripting via Media Upload
medium
The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media upload module in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.
- CVSS:
- 6.4
- Affected:
- up to 4.0.50
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2022
Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 - Stored Cross-Site Scripting via Gallery Description
medium
The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Gallery Description in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.
- CVSS:
- 6.4
- Affected:
- up to 4.0.50
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2022
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed)
unknown
The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media upload module in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.
- Affected:
- up to 4.0.50
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2022
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed)
unknown
The "Gallery Bank – WordPress Photo Gallery Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Gallery Description in versions up to, and including, 4.0.50. This can be exploited by author-level users and above.
- Affected:
- up to 4.0.50
- Fix:
- No patched version reported
- Disclosed:
- Jun 9, 2022
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Gallery Description discovered by Vishnupriya Ilango (Fortinet's FortiGuard Labs) in WordPress Gallery Bank plugin (versions <= 4.0.50).
Deactivate and delete. This plugin has been closed as of December 9, 2021 and is not available for download. Reason:...
- Affected:
- up to 4.0.50
- Fixed in:
- 4.0.50
- Disclosed:
- Jun 9, 2022
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Media Upload Module discovered by Vishnupriya Ilango (Fortinet FortiGuard Labs) in WordPress Gallery Bank plugin (versions <= 4.0.50).
Deactivate and delete. This plugin has been closed as of December 9, 2021 and is not available for download. Reason: Se...
- Affected:
- up to 4.0.50
- Fixed in:
- 4.0.50
- Disclosed:
- Jun 9, 2022
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.70 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.
- Affected:
- up to 3.0.70
- Fixed in:
- 3.0.70
- Disclosed:
- Oct 6, 2017
CVE-2014-8758 on NVD →
Gallery Bank – WordPress Photo Gallery Plugin <= 3.0.229 - SQL Injection
high
The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete_array’ parameter in versions up to, and including, 3.0.229 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...
- CVSS:
- 8.8
- Affected:
- up to 3.0.330
- Fixed in:
- 3.0.330
- Disclosed:
- Aug 21, 2015
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.330
unknown
The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘delete_array’ parameter in versions up to, and including, 3.0.229 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...
- Affected:
- up to 3.0.330
- Fixed in:
- 3.0.330
- Disclosed:
- Aug 21, 2015
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.229 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 3.0.229
- Fixed in:
- 3.0.229
- Disclosed:
- May 14, 2015
Gallery Bank – WordPress Photo Gallery <= 3.0.101 - SQL Injection
high
The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show_albums’ attribute in versions up to, and including, 3.0.101 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- CVSS:
- 8.8
- Affected:
- up to 3.0.101
- Fixed in:
- 3.0.102
- Disclosed:
- Feb 21, 2015
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.102
unknown
The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘show_albums’ attribute in versions up to, and including, 3.0.101 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- Affected:
- up to 3.0.102
- Fixed in:
- 3.0.102
- Disclosed:
- Feb 21, 2015
Gallery Bank – WordPress Photo Gallery Plugin < 3.0.61 - Arbitrary File Upload
critical
The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php in versions before 3.0.61. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possi...
- CVSS:
- 9.8
- Affected:
- up to 3.0.61
- Fixed in:
- 3.0.61
- Disclosed:
- Nov 25, 2014
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.61
unknown
The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php in versions before 3.0.61. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possi...
- Affected:
- up to 3.0.61
- Fixed in:
- 3.0.61
- Disclosed:
- Nov 25, 2014
Gallery Bank – WordPress Photo Gallery Plugin < 3.0.70 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70 for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.
- CVSS:
- 6.1
- Affected:
- up to 3.0.70
- Fixed in:
- 3.0.70
- Disclosed:
- Oct 18, 2014
CVE-2014-8758 on NVD →
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
- CVSS:
- 6.1
- Affected:
- up to 3.0.229
- Fixed in:
- 3.0.229
- Disclosed:
- Aug 1, 2014
CVE-2013-6837 on NVD →
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.229
unknown
[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
- Affected:
- up to 3.0.229
- Fixed in:
- 3.0.229
- Disclosed:
- Dec 19, 2013
CVE-2013-6837 on NVD →
Gallery Bank – WordPress Photo Gallery Plugin < 2.0.20 - Reflected Cross-Site Scripting
medium
The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via the ‘album_id’ parameter in edit_album.php and the 'recordsArray' parameter in the album_gallery_bank_class.php file in versions before 2.0.20 due to insufficient input sanitization and output es...
- CVSS:
- 6.1
- Affected:
- up to 2.0.20
- Fixed in:
- 2.0.20
- Disclosed:
- Oct 28, 2013
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20
unknown
The Gallery Bank – WordPress Photo Gallery Plugin for WordPress is vulnerable to Multiple Reflected Cross-Site Scripting via the ‘album_id’ parameter in edit_album.php and the 'recordsArray' parameter in the album_gallery_bank_class.php file in versions before 2.0.20 due to insufficient input sanitization and output es...
- Affected:
- up to 2.0.20
- Fixed in:
- 2.0.20
- Disclosed:
- Oct 28, 2013
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.61
unknown
The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by a Shell Upload security vulnerability.
- Affected:
- up to 3.0.61
- Fixed in:
- 3.0.61
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20
unknown
The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by an album-gallery-bank-class.php recordsArray Parameter Reflected XSS security vulnerability.
- Affected:
- up to 2.0.20
- Fixed in:
- 2.0.20
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20
unknown
The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by an edit-album.php album_id Parameter Reflected XSS security vulnerability.
- Affected:
- up to 2.0.20
- Fixed in:
- 2.0.20
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 2.0.20
unknown
The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by a Multiple Unspecified Issues security vulnerability.
- Affected:
- up to 2.0.20
- Fixed in:
- 2.0.20
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.102
unknown
The Gallery Bank – Responsive Photo Gallery plugin exposes a Short Code named ‘gallery_bank’, in order to allow site publishers to insert galleries into pages / posts. This Short Code is vulnerable to a UNION based SQL Injection. This is possible by manipulating the field ‘show_albums’ whe...
- Affected:
- up to 3.0.102
- Fixed in:
- 3.0.102
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.330
unknown
The WordPress Photo Gallery Plugin by Gallery Bank WordPress plugin was affected by an Authenticated Blind SQL Injection security vulnerability.
- Affected:
- up to 3.0.330
- Fixed in:
- 3.0.330
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed + closed)
unknown
The plugin does not sanitise and escape the Image Title field via the Media Upload module, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 4.0.50
- Fix:
- No patched version reported
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] <= 4.0.50 (unfixed + closed)
unknown
The plugin does not sanitise and escape the Gallery Description field, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 4.0.50
- Fix:
- No patched version reported
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 3.0.229
unknown
The jQuery prettyPhoto library bundled with many plugins was found to be vulnerable to DOM Cross-Site Scripting (XSS).
- Affected:
- up to 3.0.229
- Fixed in:
- 3.0.229
Gallery Bank – WordPress Photo Gallery Plugin [gallery-bank] < 4.0.19
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 4.0.19
- Fixed in:
- 4.0.19
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database