plugin

Global Flash Galleries Vulnerabilities

16 known security issues reported for the Global Flash Galleries WordPress plugin. Most recent disclosed Aug 1, 2023.

2 critical 1 medium

Running Global Flash Galleries on your site? Check whether your installed version is affected.

Scan your site free

Global Flash Gallery [global-flash-galleries] < 1.1

unknown

Update the plugin. An unknown person discovered and reported this SQL Injection vulnerability in WordPress Global Flash Galleries Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.1.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2023

Global Flash Gallery [global-flash-galleries] < 1.1

unknown

Update the plugin. Ashiyane Digital Security Team discovered and reported this Arbitrary File Upload vulnerability in WordPress Global Flash Galleries Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2023

Global Flash Gallery [global-flash-galleries] < 1.1

unknown

Update the plugin. Ashiyane Digital Security Team discovered and reported this Arbitrary File Upload vulnerability in WordPress Global Flash Galleries Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2023

Global Flash Gallery [global-flash-galleries] < 1.1

unknown

Upgrade the plugin. Ashiyane Digital Security Team discovered and reported this Remote File Inclusion vulnerability in WordPress Global Flash Galleries Plugin. This could allow a malicious actor to get a website to load an external website or script which will then be executed on the website. This could allow the malic...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jan 18, 2023

Global Flash Gallery <= 0.15.1 - SQL Injection

critical

The Global Flash Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘popup.php id' parameter in versions up to, and including, 0.15.2 due to insufficient escaping on the user supplied parameter and lack of sufficient reparation on the existing SQL query. This makes it possible for unauthentica...

CVSS:
9.8
Affected:
up to 0.15.1
Fixed in:
0.15.2
Disclosed:
Aug 1, 2014

Global Flash Gallery [global-flash-galleries] < 1.1 (closed)

unknown

Because of this vulnerability, attacker could use the affected system to Host files. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Global Flash Gallery [global-flash-galleries] < 1.1 (closed)

unknown

Because of this vulnerability, attacker could use the affected system to Host files. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Global Flash Gallery [global-flash-galleries] < 1.1 (closed)

unknown

This plugin is prone to an SQL injection in popup.php id parameter. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Global Flash Gallery [global-flash-galleries] < 0.15.2

unknown

The Global Flash Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘popup.php id' parameter in versions up to, and including, 0.15.2 due to insufficient escaping on the user supplied parameter and lack of sufficient reparation on the existing SQL query. This makes it possible for unauthentica...

Affected:
up to 0.15.2
Fixed in:
0.15.2
Disclosed:
Aug 1, 2014

Global Flash Gallery < 0.13.4 - Cross-Site Scripting

medium

The Global Flash Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.13.3 due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 0.13.3
Fixed in:
0.13.4
Disclosed:
May 25, 2014

Global Flash Gallery [global-flash-galleries] < 0.13.4

unknown

The Global Flash Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.13.3 due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

Affected:
up to 0.13.4
Fixed in:
0.13.4
Disclosed:
May 25, 2014

Global Flash Gallery [global-flash-galleries] < 0.10 (closed)

unknown

Global Flash Gallery plugin is prone to an arbitrary file upload vulnerability via "swfupload.php" that allows upload arbitrary files. This can result in arbitrary code execution within the context of the vulnerable application. Upgrade the plugin.

Affected:
up to 0.10
Fixed in:
0.10
Disclosed:
Jan 18, 2014

Global Flash Gallery <= 0.15.1 - Arbitrary File Upload

critical

The Global Flash Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /global-flash-galleries/swfupload.php file in versions up to, and including, 0.15.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites serve...

CVSS:
9.8
Affected:
up to 0.15.1
Fixed in:
0.15.2
Disclosed:
Sep 8, 2011

Global Flash Gallery [global-flash-galleries] < 0.15.2

unknown

The Global Flash Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /global-flash-galleries/swfupload.php file in versions up to, and including, 0.15.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites serve...

Affected:
up to 0.15.2
Fixed in:
0.15.2
Disclosed:
Sep 8, 2011

Global Flash Gallery [global-flash-galleries] <= 0.15.3 (unfixed + closed)

unknown

The global-flash-galleries WordPress plugin was affected by a popup.php id Parameter SQL Injection security vulnerability.

Affected:
up to 0.15.3
Fix:
No patched version reported

Global Flash Gallery [global-flash-galleries] <= 0.15.3 (unfixed + closed)

unknown

The global-flash-galleries WordPress plugin was affected by a swfupload.php Unauthenticated Image Upload Weakness security vulnerability.

Affected:
up to 0.15.3
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database