Unite Gallery Lite [unite-gallery-lite] <= 1.7.62 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Valiano Unite Gallery Lite.This issue affects Unite Gallery Lite: from n/a through 1.7.62.
- Affected:
- up to 1.7.62
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2024
CVE-2024-43207 on NVD →
Unite Gallery Lite <= 1.7.62 - Authenticated (Contributor+) SQL Injection
critical
The Unite Gallery Lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.62 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 9.9
- Affected:
- up to 1.7.62
- Fix:
- No patched version reported
- Disclosed:
- Aug 9, 2024
CVE-2024-43207 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.7.60 (closed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Lite allows PHP Local File Inclusion.This issue affects Unite Gallery Lite: from n/a through 1.7.59.
- Affected:
- up to 1.7.60
- Fixed in:
- 1.7.60
- Disclosed:
- May 17, 2024
CVE-2023-33310 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.7.62 (closed)
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Valiano Unite Gallery Lite plugin <= 1.7.61 versions.
- Affected:
- up to 1.7.62
- Fixed in:
- 1.7.62
- Disclosed:
- Aug 30, 2023
CVE-2023-34183 on NVD →
Unite Gallery Lite <= 1.7.61 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Unite Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, and including, 1.7.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbit...
- CVSS:
- 4.4
- Affected:
- up to 1.7.61
- Fixed in:
- 1.7.62
- Disclosed:
- May 30, 2023
CVE-2023-34183 on NVD →
Unite Gallery Lite <= 1.7.59 - Authenticated(Administrator+) Local File Inclusion via 'view' parameter
medium
The Unite Gallery Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.59 via the 'view' parameter. This allows authenticated attackers with administrator-level privileges to include and execute arbitrary files on the server, allowing the execution of any PHP code in tho...
- CVSS:
- 5
- Affected:
- up to 1.7.59
- Fixed in:
- 1.7.60
- Disclosed:
- May 22, 2023
CVE-2023-33310 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.5 (closed)
unknown
[en] The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Sep 26, 2019
CVE-2015-9445 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.5 (closed)
unknown
[en] The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Sep 26, 2019
CVE-2015-9446 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.5 (closed)
unknown
[en] The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Sep 26, 2019
CVE-2015-9447 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.4.7 (closed)
unknown
Unite Gallery Lite is prone to multiple vulnerabilities, such as CSRF and SQL injection.
Update the plugin.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Jul 27, 2015
Unite Gallery Lite <= 1.4.6 - Cross-Site Request Forgery & Authenticated SQL Injection
high
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
- CVSS:
- 8.8
- Affected:
- up to 1.4.6
- Fixed in:
- 1.5
- Disclosed:
- Jul 25, 2015
CVE-2015-9445 on NVD →
Unite Gallery Lite < 1.5 - SQL Injection
high
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
- CVSS:
- 8.8
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Jul 25, 2015
CVE-2015-9446 on NVD →
Unite Gallery Lite < 1.5 - Cross-Site Request Forgery and SQL Injection
high
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
- CVSS:
- 7.2
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Jul 25, 2015
CVE-2015-9447 on NVD →
Unite Gallery Lite [unite-gallery-lite] < 1.7.61 (closed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.7.61
- Fixed in:
- 1.7.61
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database