Photocrati [photocrati-theme] < 5.0 (unfixed)
unknown
[en] SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.
- Affected:
- up to 5.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2015
CVE-2015-2216 on NVD →
Photocrati [photocrati-theme] < 5.0
unknown
[en] Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the prod_id parameter.
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Jan 13, 2015
CVE-2014-100016 on NVD →
Photocrati [photocrati-theme] < 1.1
unknown
Because of this vulnerability, the attackers can obtain sensitive information via an invalid upload request.
Update the theme.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Aug 1, 2014
Photocrati <= 4.8.0 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the prod_id parameter.
- CVSS:
- 6.1
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.1
- Disclosed:
- Jan 29, 2014
CVE-2014-100016 on NVD →
Photocrati (Unknown Versions) - Multiple Vulnerabilities
critical
The Photocrati Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all versions. This is due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser, create fak...
- CVSS:
- 10
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2013
Photocrati [photocrati-theme] < 100 (unfixed + closed)
unknown
The Photocrati Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all versions. This is due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser, create fak...
- Affected:
- up to 100
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2013
PhotoCrati Theme <= 4.0 - SQL Injection
critical
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme up to and including version 4.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.
- CVSS:
- 9.8
- Affected:
- up to 4.0
- Fixed in:
- 4.1
- Disclosed:
- Sep 23, 2011
CVE-2015-2216 on NVD →
Photocrati [photocrati-theme] < 100 (unfixed)
unknown
The photocrati-theme WordPress theme was affected by a Full Path Disclosure security vulnerability.
- Affected:
- up to 100
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database