Photo Gallery – Responsive Image Galleries by Supsystic <= 1.16.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Photo Gallery – Responsive Image Galleries by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above...
- CVSS:
- 4.4
- Affected:
- up to 1.16.3
- Fixed in:
- 1.17.0
- Disclosed:
- Jul 22, 2026
CVE-2026-24628 on NVD →
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.15.17
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Photo Gallery by Supsystic allows Stored XSS.This issue affects Photo Gallery by Supsystic: from n/a through 1.15.16.
- Affected:
- up to 1.15.17
- Fixed in:
- 1.15.17
- Disclosed:
- Mar 27, 2024
CVE-2024-29921 on NVD →
Photo Gallery by Supsystic <= 1.15.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 5.5
- Affected:
- up to 1.15.16
- Fixed in:
- 1.15.17
- Disclosed:
- Mar 25, 2024
CVE-2024-29921 on NVD →
Photo Gallery by Supsystic <= 1.15.5 - Cross-Site Request Forgery to Plugin Settings Change
medium
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
- CVSS:
- 5.4
- Affected:
- up to 1.15.5
- Fixed in:
- 1.15.6
- Disclosed:
- Jun 15, 2022
CVE-2021-36891 on NVD →
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.15.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
- Affected:
- up to 1.15.6
- Fixed in:
- 1.15.6
- Disclosed:
- Jun 15, 2022
CVE-2021-36891 on NVD →
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6
unknown
[en] The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Aug 22, 2019
CVE-2016-10918 on NVD →
Photo Gallery by Supsystic <= 1.8.8 - Cross-Site Request Forgery
high
The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.5. This is due to missing or incorrect nonce validation on the 'updateAttachment' action. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forge...
- CVSS:
- 8.8
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Aug 15, 2016
CVE-2016-10918 on NVD →
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6
unknown
Because of this vulnerability, the attackers can add images to a gallery.
Update the plugin.
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Aug 15, 2016
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6
unknown
Because of this vulnerability, the attackers can steal users' session tokens or perform arbitrary actions on their behalf.
Update the plugin.
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Aug 14, 2016
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.2.6
unknown
WordPress Photo Gallery by Supsystic plugin unrestricted file upload vulnerability allows an access to upload functionality via "UploadHandler.php".
Update to version 1.2.6.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Nov 11, 2014
Photo Gallery by Supsystic [gallery-by-supsystic] < 1.8.6
unknown
The plugin does not have CSRF check in place and it lacking sanitisation as well as escaping via in AJAX action to update attachment, which could lead to Stored XSS via CSRF
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database