Robo Gallery <= 5.1.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. The plugin uses a custom `|***...***|` marker pattern in its `fixJsFunction()` method to embed raw JavaScript function references within JSON-encoded configurat...
- CVSS:
- 6.4
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- Apr 7, 2026
CVE-2026-4300 on NVD →
Robo Gallery <= 5.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.4
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Feb 14, 2026
CVE-2026-32356 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.23
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.24
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisi...
- Affected:
- up to 3.2.24
- Fixed in:
- 3.2.24
- Disclosed:
- May 15, 2025
CVE-2024-13384 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.22
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in m...
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.22
- Disclosed:
- May 15, 2025
CVE-2024-10144 on NVD →
Robo Gallery <= 5.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 4.4
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- May 7, 2025
CVE-2025-47521 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 5.0.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery allows Stored XSS. This issue affects Robo Gallery: from n/a through 5.0.2.
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- May 7, 2025
CVE-2025-47521 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 3.2.21
- Fixed in:
- 3.2.22
- Disclosed:
- Mar 11, 2025
CVE-2024-10144 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.23 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve...
- CVSS:
- 4.4
- Affected:
- up to 3.2.23
- Fixed in:
- 3.2.24
- Disclosed:
- Mar 3, 2025
CVE-2024-13384 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.22
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.22
- Disclosed:
- Jan 7, 2025
CVE-2024-10102 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 3.2.21
- Fixed in:
- 3.2.22
- Disclosed:
- Dec 17, 2024
CVE-2024-10102 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.11
unknown
[en] Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robo Gallery: from n/a through 3.2.9.
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.11
- Disclosed:
- Dec 13, 2024
CVE-2022-45841 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.22
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RoboSoft Robo Gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through 3.2.21.
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.22
- Disclosed:
- Oct 24, 2024
CVE-2024-49696 on NVD →
Robo Gallery <= 3.2.21 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 3.2.21
- Fixed in:
- 3.2.22
- Disclosed:
- Oct 21, 2024
CVE-2024-49696 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.22
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level acc...
- Affected:
- up to 3.2.22
- Fixed in:
- 3.2.22
- Disclosed:
- Oct 8, 2024
CVE-2024-8431 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access a...
- CVSS:
- 4.3
- Affected:
- up to 3.2.21
- Fixed in:
- 3.2.22
- Disclosed:
- Oct 7, 2024
CVE-2024-8431 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 3.2.19
- Fixed in:
- 3.2.20
- Disclosed:
- Jul 24, 2024
CVE-2024-3896 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.20
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...
- Affected:
- up to 3.2.20
- Fixed in:
- 3.2.20
- Disclosed:
- Jul 24, 2024
CVE-2024-3896 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.20
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level...
- Affected:
- up to 3.2.20
- Fixed in:
- 3.2.20
- Disclosed:
- Jun 19, 2024
CVE-2024-3894 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.20
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' functions. This makes it possible fo...
- Affected:
- up to 3.2.20
- Fixed in:
- 3.2.20
- Disclosed:
- Jun 19, 2024
CVE-2024-5343 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level acces...
- CVSS:
- 6.4
- Affected:
- up to 3.2.19
- Fixed in:
- 3.2.20
- Disclosed:
- Jun 18, 2024
CVE-2024-3894 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss
high
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' functions. This makes it possible for una...
- CVSS:
- 8.8
- Affected:
- up to 3.2.19
- Fixed in:
- 3.2.20
- Disclosed:
- Jun 18, 2024
CVE-2024-5343 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.19
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Robo Gallery: from n/a through 3.2.18.
- Affected:
- up to 3.2.19
- Fixed in:
- 3.2.19
- Disclosed:
- May 6, 2024
CVE-2024-34382 on NVD →
Robo Gallery <= 3.2.18 - Unauthenticated Information Exposure
medium
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.18. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.2.18
- Fixed in:
- 3.2.19
- Disclosed:
- May 3, 2024
CVE-2024-34382 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.18
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery allows Stored XSS.This issue affects Photo Gallery, Images, Slider in Rbs Image Gallery: from n/a through 3.2.17.
- Affected:
- up to 3.2.18
- Fixed in:
- 3.2.18
- Disclosed:
- Jan 31, 2024
CVE-2024-22295 on NVD →
Robo Gallery <= 3.2.17 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 3.2.17
- Fixed in:
- 3.2.18
- Disclosed:
- Jan 17, 2024
CVE-2024-22295 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.16
unknown
[en] The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisi...
- Affected:
- up to 3.2.16
- Fixed in:
- 3.2.16
- Disclosed:
- Sep 4, 2023
CVE-2023-3499 on NVD →
Robo Gallery <= 3.2.15 - Authenticated(Administrator+) Stored Cross-Site Scripting
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitr...
- CVSS:
- 4.4
- Affected:
- up to 3.2.15
- Fixed in:
- 3.2.16
- Disclosed:
- Aug 15, 2023
CVE-2023-3499 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.12
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.11 versions.
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.12
- Disclosed:
- May 20, 2023
CVE-2023-24414 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.13
unknown
[en] Auth. (contributor+) Stored Cross-site Scripting (XSS) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.12 versions.
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Apr 7, 2023
CVE-2023-27620 on NVD →
Robo Gallery <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes
medium
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- CVSS:
- 6.4
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.13
- Disclosed:
- Mar 13, 2023
CVE-2023-27620 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.11
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugin deactivate & activate.
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.11
- Disclosed:
- Mar 1, 2023
CVE-2022-45804 on NVD →
Robo Gallery <= 3.2.9 - Cross-Site Request Forgery via getPluginStatus
medium
The Robo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.9. This is due to missing or incorrect nonce validation on the getPluginStatus function. This makes it possible for unauthenticated attackers to activate plugins via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.11
- Disclosed:
- Feb 2, 2023
CVE-2022-45804 on NVD →
Robo Gallery Plugin <= 3.2.11 - Cross-Site Request Forgery
medium
The Robo Gallery Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.11. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform actions via forged request granted they can trick a site administrator into pe...
- CVSS:
- 4.3
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.12
- Disclosed:
- Jan 30, 2023
CVE-2023-24414 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.9 - Missing Authorization
high
The Robo Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 3.2.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create articles, list posts, activate and dea...
- CVSS:
- 8.1
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.11
- Disclosed:
- Dec 12, 2022
CVE-2022-45841 on NVD →
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.11
unknown
The Robo Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 3.2.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create articles, list posts, activate and dea...
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.11
- Disclosed:
- Dec 12, 2022
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 2.0.17
unknown
WordPress Robo Gallery plugin Privilege Escalation Vulnerability exists in 2.0.15 version. It doesn't check if the current user is administrator so any logged in user can reset allery’s view count.
Update the plugin.
- Affected:
- up to 2.0.17
- Fixed in:
- 2.0.17
- Disclosed:
- Apr 12, 2017
Photo Gallery, Images, Slider in Rbs Image Gallery <= 2.0.14 - Remote Code Execution
critical
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the vulnerable parameter 'function' that is supplied via the wp_ajax_rbs_gallery AJAX action. This allows unauthenticated attackers to execute code on the serve...
- CVSS:
- 9.8
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Apr 12, 2016
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 2.0.15
unknown
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the vulnerable parameter 'function' that is supplied via the wp_ajax_rbs_gallery AJAX action. This allows unauthenticated attackers to execute code on the serve...
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Apr 12, 2016
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 2.0.15
unknown
This plugin is prone to a remote code execution vulnerability. It allows the attackers to execute own malicious php commands to compromise the web-application or connected dbms.
Update the plugin.
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Apr 12, 2016
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 2.0.15
unknown
This is potentially a False Positive. Needs further investigation.
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
Photo Gallery, Images, Slider in Rbs Image Gallery [robo-gallery] < 3.2.23
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 3.2.23
- Fixed in:
- 3.2.23