Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.0 (closed)
unknown
[en] An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- Jan 21, 2020
CVE-2016-11018 on NVD →
Image Gallery - Responsive Photo Gallery < 2.0.6 - Authenticated Stored Cross-Site Scripting
medium
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the requests to edit gallery images in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrar...
- CVSS:
- 5.5
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 23, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 2.0.6 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 23, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 2.0.6 (closed)
unknown
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the requests to edit gallery images in versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrar...
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- Nov 23, 2016
Image Gallery - Responsive Photo Gallery <= 1.9.57 - Cross-Site Request Forgery
high
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.57. This is due to missing or incorrect nonce validation on the editgallery() function. This makes it possible for unauthenticated attackers to modify image galleries via a...
- CVSS:
- 8.8
- Affected:
- up to 1.9.57
- Fixed in:
- 1.9.58
- Disclosed:
- May 19, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.58
unknown
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.57. This is due to missing or incorrect nonce validation on the editgallery() function. This makes it possible for unauthenticated attackers to modify image galleries via a...
- Affected:
- up to 1.9.58
- Fixed in:
- 1.9.58
- Disclosed:
- May 19, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.0 (closed)
unknown
Huge IT Image Gallery plugin is prone to full path disclosure and SQL injection vulnerabilities.
Upgrade the plugin.
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- May 12, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.9.0 (closed)
unknown
Multiple vulnerabilities were found in Huge-IT Image Gallery 1.8.9 plugin. 1) It's prone to a SQL injection vulnerability 2) Also, there's a Full Path Disclosure vulnerability.
Update Huge-IT Image Gallery plugin to 1.9.0 version.
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- May 12, 2016
Huge-IT gallery-images <= 1.8.9 - SQL Injection
critical
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
- CVSS:
- 9.8
- Affected:
- up to 1.8.9
- Fixed in:
- 1.9.0
- Disclosed:
- May 10, 2016
CVE-2016-11018 on NVD →
Image Gallery – Responsive Photo Gallery <= 1.7.0 - Reflected Cross-Site Scripting via linkbutton
medium
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘linkbutton’ parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- CVSS:
- 6.1
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Feb 8, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1
unknown
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘linkbutton’ parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Feb 8, 2016
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Upgrade the plugin.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Feb 8, 2016
Image Gallery - Responsive Photo Gallery <= 1.5.5 - Reflected Cross-Site Scripting
medium
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order_by’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Aug 20, 2015
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.5.6 (closed)
unknown
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order_by’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web sc...
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Aug 20, 2015
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.5.6 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Aug 20, 2015
Image Gallery - Responsive Photo Gallery <= 1.7.0 - Reflected Cross-Site Scripting via thumbtext
medium
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘thumbtext' parameters in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Mar 12, 2015
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1
unknown
The Image Gallery - Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘thumbtext' parameters in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Mar 12, 2015
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.0.8 (closed)
unknown
[en] SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Sep 22, 2014
CVE-2014-7153 on NVD →
Image Gallery - Responsive Photo Gallery <= 1.0.7 - SQL Injection
high
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin <= 1.0.7 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
- CVSS:
- 8.8
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Sep 2, 2014
CVE-2014-7153 on NVD →
Image Gallery – Responsive Photo Gallery [gallery-images] < 2.0.6 (closed)
unknown
The gallery-images WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.7.1 (closed)
unknown
The gallery-images WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
Image Gallery – Responsive Photo Gallery [gallery-images] < 1.5.6 (closed)
unknown
The gallery-images WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database