Gmedia Photo Gallery <= 1.24.1 - Cross-Site Request Forgery
medium
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.24.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 1.24.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-63014 on NVD →
Gmedia Photo Gallery [grand-media] <= 1.24.1 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Serhii Pasyuk Gmedia Photo Gallery allows Cross Site Request Forgery.This issue affects Gmedia Photo Gallery: from n/a through 1.24.1.
- Affected:
- up to 1.24.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-63014 on NVD →
Gmedia Photo Gallery <= 1.23.0 - Authenticated (Contributor+) Local File Inclusion
high
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.23.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those...
- CVSS:
- 7.5
- Affected:
- up to 1.23.0
- Fixed in:
- 1.24.0
- Disclosed:
- Jun 27, 2025
CVE-2025-53257 on NVD →
Gmedia Photo Gallery [grand-media] <= 1.23.0 (unfixed + closed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Serhii Pasyuk Gmedia Photo Gallery allows PHP Local File Inclusion. This issue affects Gmedia Photo Gallery: from n/a through 1.23.0.
- Affected:
- up to 1.23.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53257 on NVD →
Gmedia Photo Gallery [grand-media] < 1.20.0 (closed)
unknown
[en] The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed
- Affected:
- up to 1.20.0
- Fixed in:
- 1.20.0
- Disclosed:
- May 16, 2022
CVE-2022-0873 on NVD →
Gmedia Photo Gallery < 1.20.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 1.20.0
- Fixed in:
- 1.20.0
- Disclosed:
- Apr 25, 2022
CVE-2022-0873 on NVD →
Gmedia Photo Gallery [grand-media] < 1.18.5 (closed)
unknown
Multiple Cross-Site Scripting (XSS) vulnerabilities were discovered by Vishnupriya Ilango in the WordPress Gmedia Photo Gallery plugin (versions <= 1.18.4).
- Affected:
- up to 1.18.5
- Fixed in:
- 1.18.5
- Disclosed:
- Apr 28, 2020
Gmedia Photo Gallery <= 1.18.4 - Cross-Site Scripting
medium
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.18.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.18.5
- Fixed in:
- 1.18.5
- Disclosed:
- Apr 27, 2020
Gmedia Photo Gallery [grand-media] < 1.18.5 (closed)
unknown
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.18.5 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.18.5
- Fixed in:
- 1.18.5
- Disclosed:
- Apr 27, 2020
Gmedia Photo Gallery <= 1.6.4 - Local File Inclusion
critical
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access...
- CVSS:
- 9.8
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
Gmedia Photo Gallery <= 1.6.4 - Denial of Service
high
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 1.6.4. This is due to improper redirect handling. This makes it possible for unauthenticated attackers to send requests that recursively call 301 redirects, rendering the server unavailable.
- CVSS:
- 7.5
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
Gmedia Photo Gallery <= 1.6.4 - Cross-Site Scripting
medium
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
Gmedia Photo Gallery <= 1.6.4 - Open Proxy
medium
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Open Proxy attacks in versions up to, and including, 1.6.4. This is due to inclusion of a script intended to load images from a url that doesn't end in an image file extension. This makes it possible for unauthenticated attackers to proxy through the server...
- CVSS:
- 5.8
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
CVE-2015-4339 on NVD →
Gmedia Photo Gallery [grand-media] < 1.6.5 (closed)
unknown
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
Gmedia Photo Gallery [grand-media] < 1.6.5 (closed)
unknown
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 1.6.4. This is due to improper redirect handling. This makes it possible for unauthenticated attackers to send requests that recursively call 301 redirects, rendering the server unavailable.
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
Gmedia Photo Gallery [grand-media] < 1.6.5 (closed)
unknown
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access...
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- May 27, 2015
Gmedia Photo Gallery [grand-media] < 1.2.2 (closed)
unknown
Because of this vulnerability, any user could upload PHP files.
Update the plugin.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Sep 17, 2014
Gmedia Photo Gallery < 1.2.2 - Arbitrary File Upload
critical
The Gmedia Photo Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the addmedia.php file in versions before 1.2.2. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 2, 2014
Gmedia Photo Gallery [grand-media] < 1.2.2 (closed)
unknown
The Gmedia Photo Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the addmedia.php file in versions before 1.2.2. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 2, 2014
Gmedia Photo Gallery < 0.9.4 - Reflected Cross-Site Scripting
medium
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9.3 due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 0.9.3
- Fixed in:
- 0.9.4
- Disclosed:
- May 25, 2014
Gmedia Photo Gallery [grand-media] < 0.9.4 (closed)
unknown
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.9.3 due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- Affected:
- up to 0.9.4
- Fixed in:
- 0.9.4
- Disclosed:
- May 25, 2014
Gmedia Photo Gallery [grand-media] < 1.6.5 (closed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
CVE-2015-4339 on NVD →
Gmedia Photo Gallery [grand-media] < 1.18.5 (closed)
unknown
Multiple XSS vulnerabilities were discovered in the Gmedia Gallery plugin (version 1.18.0) WordPress plugin. These vulnerabilities were caused by improper validation of user input in the album, gallery, category and media upload module. The vulnerability types include both stored and reflected XSS.
- Affected:
- up to 1.18.5
- Fixed in:
- 1.18.5
Gmedia Photo Gallery [grand-media] < 1.2.2 (closed)
unknown
The Gmedia Photo Gallery WordPress plugin was affected by a Shell Upload security vulnerability.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database