Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute
medium
The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.6
- Disclosed:
- Jun 17, 2026
CVE-2026-2021 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.8.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Slideshow Gallery allows Stored XSS.This issue affects Slideshow Gallery: from n/a through 1.8.3.
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Oct 5, 2024
CVE-2024-47376 on NVD →
Slideshow Gallery <= 1.8.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Slideshow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 4.4
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Sep 30, 2024
CVE-2024-47376 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.8.2
unknown
[en] The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentica...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Jun 12, 2024
CVE-2024-5543 on NVD →
Slideshow Gallery LITE <= 1.8.1 - Authenticated (Contributor+) SQL Injection
high
The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...
- CVSS:
- 8.1
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.2
- Disclosed:
- Jun 11, 2024
CVE-2024-5543 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.7.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Apr 12, 2024
CVE-2024-31354 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.8.1
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Apr 10, 2024
CVE-2024-31353 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.7.9
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Apr 10, 2024
CVE-2024-31355 on NVD →
Slideshow Gallery <= 1.7.8 - Authenticated (Contributor+) SQL Injection
critical
The Slideshow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access a...
- CVSS:
- 9.9
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Apr 7, 2024
CVE-2024-31355 on NVD →
Slideshow Gallery <= 1.8 - Unauthenticated Sensitive Information Exposure
medium
The Slideshow Gallery LITE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.8
- Fixed in:
- 1.8.1
- Disclosed:
- Apr 7, 2024
CVE-2024-31353 on NVD →
Slideshow Gallery <= 1.7.8 - Cross-Site Request Forgery
medium
The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Apr 7, 2024
CVE-2024-31354 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.7.7
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: from n/a through 1.7.6.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Dec 20, 2023
CVE-2023-28491 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.7.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Nov 12, 2023
CVE-2023-28497 on NVD →
Slideshow Gallery LITE <= 1.7.6 - Authenticated(Admin+) SQL Injection
medium
The Slideshow Gallery LITE plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers w...
- CVSS:
- 6.5
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2023
CVE-2023-28491 on NVD →
Slideshow Gallery LITE <= 1.7.6 - Cross-Site Request Forgery via admin_slides
medium
The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_slides function. This makes it possible for unauthenticated attackers to delete slides via forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2023
CVE-2023-28497 on NVD →
Slideshow Gallery LITE <= 1.7.6 - Cross-Site Request Forgery via admin_galleries
medium
The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_galleries function. This makes it possible for unauthenticated attackers to delete galleries via forged request granted t...
- CVSS:
- 4.3
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2023
CVE-2023-28497 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.7.7
unknown
The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_galleries function. This makes it possible for unauthenticated attackers to delete galleries via forged request granted t...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2023
Slideshow Gallery LITE [slideshow-gallery] < 1.7.7
unknown
The Slideshow Gallery LITE plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers w...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2023
Slideshow Gallery LITE [slideshow-gallery] < 1.7.7
unknown
The Slideshow Gallery LITE plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the admin_slides function. This makes it possible for unauthenticated attackers to delete slides via forged request granted they ca...
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Mar 15, 2023
Slideshow Gallery LITE [slideshow-gallery] < 1.7.4
unknown
[en] The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Nov 23, 2021
CVE-2021-24882 on NVD →
Slideshow Gallery < 1.7.4 - Cross-Site Scripting
medium
The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Oct 25, 2021
CVE-2021-24882 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.6.9
unknown
[en] XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
- Affected:
- up to 1.6.9
- Fixed in:
- 1.6.9
- Disclosed:
- Apr 15, 2019
CVE-2018-18019 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.6.9
unknown
[en] XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
- Affected:
- up to 1.6.9
- Fixed in:
- 1.6.9
- Disclosed:
- Apr 15, 2019
CVE-2018-18017 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.6.9
unknown
[en] SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
- Affected:
- up to 1.6.9
- Fixed in:
- 1.6.9
- Disclosed:
- Apr 15, 2019
CVE-2018-18018 on NVD →
Slideshow Gallery <= 1.6.8 - SQL Injection
high
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.9
- Disclosed:
- Oct 4, 2018
CVE-2018-18018 on NVD →
Slideshow Gallery <= 1.6.8 - Cross-Site Scripting
medium
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.9
- Disclosed:
- Oct 4, 2018
CVE-2018-18019 on NVD →
Slideshow Gallery <= 1.6.8 - Cross-Site Scripting
medium
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.9
- Disclosed:
- Oct 4, 2018
CVE-2018-18017 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.6.6.1
unknown
[en] The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
- Affected:
- up to 1.6.6.1
- Fixed in:
- 1.6.6.1
- Disclosed:
- Oct 3, 2018
CVE-2018-17946 on NVD →
Slideshow Gallery <= 1.6.5 - Reflected Cross-Site Scripting
medium
The Tribulant Slideshow Gallery plugin before 1.6.6 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Apr 10, 2017
CVE-2018-17946 on NVD →
Slideshow Gallery <= 1.6.5 - Cross-Site Scripting via method
medium
The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' parameter in versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Mar 1, 2017
Slideshow Gallery LITE [slideshow-gallery] < 1.6.6
unknown
The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'method' parameter in versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Mar 1, 2017
Slideshow Gallery <= 1.6 - Cross-Site Scripting
medium
The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order’ parameter in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- CVSS:
- 6.1
- Affected:
- up to 1.6
- Fixed in:
- 1.6.1
- Disclosed:
- Mar 21, 2016
Slideshow Gallery LITE [slideshow-gallery] < 1.6.1
unknown
The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘order’ parameter in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Mar 21, 2016
Slideshow Gallery <= 1.5.3.1 - Cross-Site Request Forgery to Arbitrary File Upload
high
The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.3.1. This is due to missing nonce validation on the save slideshow functionality. This makes it possible for unauthenticated attackers to upload arbitrary files, including php files, and inject m...
- CVSS:
- 8.8
- Affected:
- up to 1.5.3.1
- Fixed in:
- 1.5.3.2
- Disclosed:
- Aug 20, 2015
Slideshow Gallery <= 1.5.3.2 - Reflected Cross-Site Scripting
medium
The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ parameter in versions up to, and including, 1.5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 6.1
- Affected:
- up to 1.5.3.4
- Fixed in:
- 1.5.3.4
- Disclosed:
- Aug 20, 2015
Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.2
unknown
The Slideshow Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.3.1. This is due to missing nonce validation on the save slideshow functionality. This makes it possible for unauthenticated attackers to upload arbitrary files, including php files, and inject m...
- Affected:
- up to 1.5.3.2
- Fixed in:
- 1.5.3.2
- Disclosed:
- Aug 20, 2015
Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.4
unknown
The Slideshow Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Gallerymessage’ parameter in versions up to, and including, 1.5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 1.5.3.4
- Fixed in:
- 1.5.3.4
- Disclosed:
- Aug 20, 2015
Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.4
unknown
This plugin is prone to an arbitrary file upload and cross site scripting vulnerabilities. Authenticated administrators can upload arbitrary files and store HTML or JS codes because of them.
Update the plugin.
- Affected:
- up to 1.5.3.4
- Fixed in:
- 1.5.3.4
- Disclosed:
- Aug 20, 2015
Slideshow Gallery LITE [slideshow-gallery] < 1.4.7
unknown
[en] Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Sep 11, 2014
CVE-2014-5460 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.4.7
unknown
Slideshow Gallery plugin is prone to a sehll upload vulnerability. It allows an attacker to upload any PHP file remotely to the vulnerable website.
Upgrade the plugin.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Sep 1, 2014
Slideshow Gallery < 1.4.7 - Arbitrary File Upload
high
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
- CVSS:
- 8.8
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 29, 2014
CVE-2014-5460 on NVD →
Slideshow Gallery LITE [slideshow-gallery] < 1.5.3.4
unknown
The Slideshow Gallery WordPress plugin was affected by an Arbitrary file upload & Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.5.3.4
- Fixed in:
- 1.5.3.4
Slideshow Gallery LITE [slideshow-gallery] < 1.6.5
unknown
The Slideshow Gallery WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5