plugin

Slideshow Gallery Vulnerabilities

43 known security issues reported for the Slideshow Gallery WordPress plugin. Most recent disclosed Jun 17, 2026.

1 critical 4 high 14 medium

Running Slideshow Gallery on your site? Check whether your installed version is affected.

Scan your site free

Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute

medium

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 1.8.5
Fixed in:
1.8.6
Disclosed:
Jun 17, 2026

CVE-2026-2021 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.8.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Slideshow Gallery allows Stored XSS.This issue affects Slideshow Gallery: from n/a through 1.8.3.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Oct 5, 2024

CVE-2024-47376 on NVD →

Slideshow Gallery <= 1.8.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Slideshow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pa...

CVSS:
4.4
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Sep 30, 2024

CVE-2024-47376 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.8.2

unknown

[en] The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Jun 12, 2024

CVE-2024-5543 on NVD →

Slideshow Gallery LITE <= 1.8.1 - Authenticated (Contributor+) SQL Injection

high

The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...

CVSS:
8.1
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Jun 11, 2024

CVE-2024-5543 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.7.9

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.

Affected:
up to 1.7.9
Fixed in:
1.7.9
Disclosed:
Apr 12, 2024

CVE-2024-31354 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.8.1

unknown

[en] Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Apr 10, 2024

CVE-2024-31353 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.7.9

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.

Affected:
up to 1.7.9
Fixed in:
1.7.9
Disclosed:
Apr 10, 2024

CVE-2024-31355 on NVD →

Slideshow Gallery <= 1.7.8 - Authenticated (Contributor+) SQL Injection

critical

The Slideshow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access a...

CVSS:
9.9
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Apr 7, 2024

CVE-2024-31355 on NVD →

Slideshow Gallery <= 1.8 - Unauthenticated Sensitive Information Exposure

medium

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.8
Fixed in:
1.8.1
Disclosed:
Apr 7, 2024

CVE-2024-31353 on NVD →

Slideshow Gallery <= 1.7.8 - Cross-Site Request Forgery

medium

The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...

CVSS:
4.3
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Apr 7, 2024

CVE-2024-31354 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.7.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: from n/a through 1.7.6.

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Dec 20, 2023

CVE-2023-28491 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.7.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Nov 12, 2023

CVE-2023-28497 on NVD →

Slideshow Gallery LITE <= 1.7.6 - Authenticated(Admin+) SQL Injection

medium

The Slideshow Gallery LITE plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers w...

CVSS:
6.5
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Mar 15, 2023

CVE-2023-28491 on NVD →

Slideshow Gallery LITE <= 1.7.6 - Cross-Site Request Forgery via admin_slides

medium

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_slides function. This makes it possible for unauthenticated attackers to delete slides via forged request granted they ca...

CVSS:
4.3
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Mar 15, 2023

CVE-2023-28497 on NVD →

Slideshow Gallery LITE <= 1.7.6 - Cross-Site Request Forgery via admin_galleries

medium

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_galleries function. This makes it possible for unauthenticated attackers to delete galleries via forged request granted t...

CVSS:
4.3
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Mar 15, 2023

CVE-2023-28497 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.7.7

unknown

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_galleries function. This makes it possible for unauthenticated attackers to delete galleries via forged request granted t...

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Mar 15, 2023

Slideshow Gallery LITE [slideshow-gallery] < 1.7.7

unknown

The Slideshow Gallery LITE plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers w...

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Mar 15, 2023

Slideshow Gallery LITE [slideshow-gallery] < 1.7.7

unknown

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_slides function. This makes it possible for unauthenticated attackers to delete slides via forged request granted they ca...

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Mar 15, 2023

Slideshow Gallery LITE [slideshow-gallery] < 1.7.4

unknown

[en] The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Nov 23, 2021

CVE-2021-24882 on NVD →

Slideshow Gallery < 1.7.4 - Cross-Site Scripting

medium

The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVSS:
4.8
Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Oct 25, 2021

CVE-2021-24882 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.6.9

unknown

[en] XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.

Affected:
up to 1.6.9
Fixed in:
1.6.9
Disclosed:
Apr 15, 2019

CVE-2018-18019 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.6.9

unknown

[en] XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

Affected:
up to 1.6.9
Fixed in:
1.6.9
Disclosed:
Apr 15, 2019

CVE-2018-18017 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.6.9

unknown

[en] SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

Affected:
up to 1.6.9
Fixed in:
1.6.9
Disclosed:
Apr 15, 2019

CVE-2018-18018 on NVD →

Slideshow Gallery <= 1.6.8 - SQL Injection

high

SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

CVSS:
7.2
Affected:
up to 1.6.8
Fixed in:
1.6.9
Disclosed:
Oct 4, 2018

CVE-2018-18018 on NVD →

Slideshow Gallery <= 1.6.8 - Cross-Site Scripting

medium

XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.

CVSS:
6.1
Affected:
up to 1.6.8
Fixed in:
1.6.9
Disclosed:
Oct 4, 2018

CVE-2018-18019 on NVD →

Slideshow Gallery <= 1.6.8 - Cross-Site Scripting

medium

XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.

CVSS:
6.1
Affected:
up to 1.6.8
Fixed in:
1.6.9
Disclosed:
Oct 4, 2018

CVE-2018-18017 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.6.6.1

unknown

[en] The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.

Affected:
up to 1.6.6.1
Fixed in:
1.6.6.1
Disclosed:
Oct 3, 2018

CVE-2018-17946 on NVD →

Slideshow Gallery <= 1.6.5 - Reflected Cross-Site Scripting

medium

The Tribulant Slideshow Gallery plugin before 1.6.6 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.

CVSS:
6.1
Affected:
up to 1.6.5
Fixed in:
1.6.6
Disclosed:
Apr 10, 2017

CVE-2018-17946 on NVD →

Slideshow Gallery <= 1.6.5 - Cross-Site Scripting via method

medium

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' parameter in versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 1.6.5
Fixed in:
1.6.6
Disclosed:
Mar 1, 2017

Slideshow Gallery LITE [slideshow-gallery] < 1.6.6

unknown

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' parameter in versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Mar 1, 2017

Slideshow Gallery <= 1.6 - Cross-Site Scripting

medium

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order’ parameter in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 1.6
Fixed in:
1.6.1
Disclosed:
Mar 21, 2016

Slideshow Gallery LITE [slideshow-gallery] < 1.6.1

unknown

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order’ parameter in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Mar 21, 2016

Slideshow Gallery <= 1.5.3.1 - Cross-Site Request Forgery to Arbitrary File Upload

high

The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.3.1. This is due to missing nonce validation on the save slideshow functionality. This makes it possible for unauthenticated attackers to upload arbitrary files, including php files, and inject m...

CVSS:
8.8
Affected:
up to 1.5.3.1
Fixed in:
1.5.3.2
Disclosed:
Aug 20, 2015

Slideshow Gallery <= 1.5.3.2 - Reflected Cross-Site Scripting

medium

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ parameter in versions up to, and including, 1.5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 1.5.3.4
Fixed in:
1.5.3.4
Disclosed:
Aug 20, 2015

Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.2

unknown

The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.3.1. This is due to missing nonce validation on the save slideshow functionality. This makes it possible for unauthenticated attackers to upload arbitrary files, including php files, and inject m...

Affected:
up to 1.5.3.2
Fixed in:
1.5.3.2
Disclosed:
Aug 20, 2015

Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.4

unknown

The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ parameter in versions up to, and including, 1.5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 1.5.3.4
Fixed in:
1.5.3.4
Disclosed:
Aug 20, 2015

Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.4

unknown

This plugin is prone to an arbitrary file upload and cross site scripting vulnerabilities. Authenticated administrators can upload arbitrary files and store HTML or JS codes because of them. Update the plugin.

Affected:
up to 1.5.3.4
Fixed in:
1.5.3.4
Disclosed:
Aug 20, 2015

Slideshow Gallery LITE [slideshow-gallery] < 1.4.7

unknown

[en] Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Sep 11, 2014

CVE-2014-5460 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.4.7

unknown

Slideshow Gallery plugin is prone to a sehll upload vulnerability. It allows an attacker to upload any PHP file remotely to the vulnerable website. Upgrade the plugin.

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Sep 1, 2014

Slideshow Gallery < 1.4.7 - Arbitrary File Upload

high

Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

CVSS:
8.8
Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Aug 29, 2014

CVE-2014-5460 on NVD →

Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.4

unknown

The Slideshow Gallery WordPress plugin was affected by an Arbitrary file upload &amp; Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.5.3.4
Fixed in:
1.5.3.4

Slideshow Gallery LITE [slideshow-gallery] < 1.6.5

unknown

The Slideshow Gallery WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.6.5
Fixed in:
1.6.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database