plugin

Gallery Images Vulnerabilities

22 known security issues reported for the Gallery Images WordPress plugin. Most recent disclosed Jan 21, 2020.

1 critical 2 high 4 medium

Running Gallery Images on your site? Check whether your installed version is affected.

Scan your site free

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.0 (closed)

unknown

[en] An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
Jan 21, 2020

CVE-2016-11018 on NVD →

Image Gallery - Responsive Photo Gallery < 2.0.6 - Authenticated Stored Cross-Site Scripting

medium

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the requests to edit gallery images in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrar...

CVSS:
5.5
Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Nov 23, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 2.0.6 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Nov 23, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 2.0.6 (closed)

unknown

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the requests to edit gallery images in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrar...

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Nov 23, 2016

Image Gallery - Responsive Photo Gallery <= 1.9.57 - Cross-Site Request Forgery

high

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.57. This is due to missing or incorrect nonce validation on the editgallery() function. This makes it possible for unauthenticated attackers to modify image galleries via a...

CVSS:
8.8
Affected:
up to 1.9.57
Fixed in:
1.9.58
Disclosed:
May 19, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.58

unknown

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.57. This is due to missing or incorrect nonce validation on the editgallery() function. This makes it possible for unauthenticated attackers to modify image galleries via a...

Affected:
up to 1.9.58
Fixed in:
1.9.58
Disclosed:
May 19, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.0 (closed)

unknown

Huge IT Image Gallery plugin is prone to full path disclosure and SQL injection vulnerabilities. Upgrade the plugin.

Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
May 12, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.0 (closed)

unknown

Multiple vulnerabilities were found in Huge-IT Image Gallery 1.8.9 plugin. 1) It's prone to a SQL injection vulnerability 2) Also, there's a Full Path Disclosure vulnerability. Update Huge-IT Image Gallery plugin to 1.9.0 version.

Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
May 12, 2016

Huge-IT gallery-images <= 1.8.9 - SQL Injection

critical

An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

CVSS:
9.8
Affected:
up to 1.8.9
Fixed in:
1.9.0
Disclosed:
May 10, 2016

CVE-2016-11018 on NVD →

Image Gallery – Responsive Photo Gallery <= 1.7.0 - Reflected Cross-Site Scripting via linkbutton

medium

The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘linkbutton’ parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

CVSS:
6.1
Affected:
up to 1.7.0
Fixed in:
1.7.1
Disclosed:
Feb 8, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1

unknown

The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘linkbutton’ parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Feb 8, 2016

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade the plugin.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Feb 8, 2016

Image Gallery - Responsive Photo Gallery <= 1.5.5 - Reflected Cross-Site Scripting

medium

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order_by’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web sc...

CVSS:
6.1
Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 20, 2015

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.5.6 (closed)

unknown

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order_by’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web sc...

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 20, 2015

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.5.6 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Aug 20, 2015

Image Gallery - Responsive Photo Gallery <= 1.7.0 - Reflected Cross-Site Scripting via thumbtext

medium

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘thumbtext' parameters in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Mar 12, 2015

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1

unknown

The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘thumbtext' parameters in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pag...

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Mar 12, 2015

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.0.8 (closed)

unknown

[en] SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Sep 22, 2014

CVE-2014-7153 on NVD →

Image Gallery - Responsive Photo Gallery <= 1.0.7 - SQL Injection

high

SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin <= 1.0.7 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.

CVSS:
8.8
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Sep 2, 2014

CVE-2014-7153 on NVD →

Image Gallery – Responsive Photo Gallery [gallery-images] < 2.0.6 (closed)

unknown

The gallery-images WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.0.6
Fixed in:
2.0.6

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1 (closed)

unknown

The gallery-images WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.7.1
Fixed in:
1.7.1

Image Gallery – Responsive Photo Gallery [gallery-images] < 1.5.6 (closed)

unknown

The gallery-images WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.5.6
Fixed in:
1.5.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database