| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-12403 | Image Gallery – Responsive Photo Gallery <= 1.0.5 - Reflected Cross-Site Scripting | realwebcare | Awesome Responsive Photo Gallery – Image & Video Lightbox Gallery | Medium | 6.1 | 2025-01-15 09:25:55 | Deep Dive |
| CVE-2024-12853 | Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload | wpchill | Modula Image Gallery – Photo Grid & Video Gallery | High | 8.8 | 2025-01-08 09:18:37 | Deep Dive |
| CVE-2025-22518 | WordPress Justified Image Gallery plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | PluginsPoint | Justified Image Gallery | Medium | 6.5 | 2025-01-07 14:57:34 | Deep Dive |
| CVE-2025-22543 | WordPress ST Gallery WP plugin <= 1.0.8 - Settings Change vulnerability | beautifultemplates | ST Gallery WP | Medium | 5.4 | 2025-01-07 14:57:23 | Deep Dive |
| CVE-2025-22353 | WordPress BVD Easy Gallery Manager plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability | bvads | BVD Easy Gallery Manager | 高危 | - | 2025-01-07 10:48:38 | Deep Dive |
| CVE-2024-12624 | Sina Extension for Elementor <= 3.5.91 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Sina Image Differ | shaonsina | Sina Extension for Elementor | Medium | 6.4 | 2025-01-07 06:40:57 | Deep Dive |
| CVE-2024-10102 | Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.22 - Contributor+ Stored XSS | Unknown | Photo Gallery, Images, Slider in Rbs Image Gallery | 中危 | - | 2025-01-07 06:00:02 | Deep Dive |
| CVE-2024-12590 | WP Youtube Gallery <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | india-web-developer | WP Youtube Gallery | Medium | 6.4 | 2025-01-07 03:21:53 | Deep Dive |
| CVE-2024-12237 | Photo Gallery Slideshow & Masonry Tiled Gallery <= 1.0.15 - Authenticated (Subscriber+) Limited Server-Side Request Forgery | nik00726 | Photo Gallery Slideshow & Masonry Tiled Gallery | Medium | 4.3 | 2025-01-03 22:22:06 | Deep Dive |
| CVE-2022-41995 | WordPress Photo Gallery – Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control | Galleryape | Gallery Images Ape | Medium | 4.3 | 2025-01-02 14:51:06 | Deep Dive |
| CVE-2024-56237 | WordPress Contest Gallery plugin <= 24.0.3 - Cross Site Scripting (XSS) vulnerability | Wasiliy Strecker / ContestGallery developer | Contest Gallery | Medium | 5.9 | 2025-01-02 12:01:15 | Deep Dive |
| CVE-2023-45631 | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability | wpdevart | Responsive Image Gallery, Gallery Album | Medium | 4.3 | 2025-01-02 11:59:52 | Deep Dive |
| CVE-2024-12096 | Exhibit to WP Gallery <= 0.0.2 - Reflected XSS | Unknown | Exhibit to WP Gallery | 中危 | - | 2024-12-24 06:00:09 | Deep Dive |
| CVE-2024-53276 | GHSL-2024-092: Open CORS policy in home-gallery | xemle | home-gallery | 中危 | - | 2024-12-23 17:13:46 | Deep Dive |
| CVE-2024-53275 | GHSL-2024-091: DNS rebinding attack in home-gallery | xemle | home-gallery | 中危 | - | 2024-12-23 17:13:43 | Deep Dive |
| CVE-2024-11900 | Portfolio – Filterable Masonry Portfolio Gallery for Professionals <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | logichunt | Portfolio – Filterable Masonry Portfolio Gallery for Professionals | Medium | 6.4 | 2024-12-16 23:24:17 | Deep Dive |
| CVE-2024-54370 | WordPress Video & Photo Gallery for Ultimate Member plugin <= 1.1.0 - Arbitrary File Upload vulnerability | SuitePlugins | Video & Photo Gallery for Ultimate Member | Critical | 9.9 | 2024-12-16 14:31:32 | Deep Dive |
| CVE-2024-55981 | WordPress Nabz Image Gallery plugin <= v1.00 - SQL Injection vulnerability | Nabajit Roy | Nabz Image Gallery | Critical | 9.3 | 2024-12-16 14:31:19 | Deep Dive |
| CVE-2023-41866 | WordPress Automatic YouTube Gallery plugin <= 2.3.3 - Broken Access Control vulnerability | Plugins360 Labs | Automatic YouTube Gallery | Medium | 4.3 | 2024-12-13 14:24:22 | Deep Dive |
| CVE-2023-40213 | WordPress Justified Gallery plugin <= 1.7.3 - Broken Access Control vulnerability | Damian Góra | Justified Gallery | Medium | 4.3 | 2024-12-13 14:24:07 | Deep Dive |