| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-8431 | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure | robosoft | Robo Gallery – Photo & Image Slider | Medium | 4.3 | 2024-10-08 11:34:19 | Deep Dive |
| CVE-2024-8543 | Slider comparison image before and after <= 0.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | hardwaremaster | Slider comparison image before and after | Medium | 6.4 | 2024-09-10 09:30:18 | Deep Dive |
| CVE-2023-4604 | Slideshow, Image Slider by 2J <= 1.3.54 - Reflected Cross-Site Scripting via 'post' | 2j-slideshow | Slideshow, Image Slider by 2J | Medium | 6.1 | 2024-08-17 07:34:25 | Deep Dive |
| CVE-2024-4389 | Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload | averta | Depicter — Popup & Slider Builder | High | 8.8 | 2024-08-14 08:29:44 | Deep Dive |
| CVE-2024-7150 | Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter | 10web | Slider by 10Web – Responsive Image Slider | High | 8.8 | 2024-08-08 05:31:46 | Deep Dive |
| CVE-2024-3896 | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title | robosoft | Robo Gallery – Photo & Image Slider | Medium | 6.4 | 2024-07-24 12:43:38 | Deep Dive |
| CVE-2024-37215 | WordPress Transition Slider – Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) vulnerability | creativeinteractivemedia | Transition Slider – Responsive Image Slider and Gallery | Medium | 5.9 | 2024-07-22 09:28:51 | Deep Dive |
| CVE-2024-4390 | Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation | averta | Depicter — Popup & Slider Builder | Medium | 6.5 | 2024-06-20 03:37:23 | Deep Dive |
| CVE-2024-3894 | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title | robosoft | Robo Gallery – Photo & Image Slider | Medium | 6.4 | 2024-06-19 06:55:46 | Deep Dive |
| CVE-2024-5343 | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss | robosoft | Robo Gallery – Photo & Image Slider | High | 8.8 | 2024-06-19 05:37:43 | Deep Dive |
| CVE-2024-35722 | WordPress Slider Responsive Slideshow – Image slider, Gallery slideshow plugin <= 1.4.0 - Broken Access Control vulnerability | A WP Life | Slider Responsive Slideshow – Image slider, Gallery slideshow | Medium | 4.3 | 2024-06-10 07:56:46 | Deep Dive |
| CVE-2023-25457 | WordPress Slider Carousel – Responsive Image Slider plugin <=1.5.1 - Broken Access Control vulnerability | Richteam | Slider Carousel – Responsive Image Slider | Medium | 5.3 | 2024-05-03 07:35:50 | Deep Dive |
| CVE-2024-32707 | WordPress Image Slider plugin <= 1.1.125 - Cross Site Scripting (XSS) vulnerability | GhozyLab | Image Slider Widget | Medium | 5.9 | 2024-04-24 10:12:13 | Deep Dive |
| CVE-2024-3020 | Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection | shapedplugin | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | High | 7.2 | 2024-04-10 04:30:22 | Deep Dive |
| CVE-2024-2949 | Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' | shapedplugin | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | Medium | 6.4 | 2024-04-06 06:47:19 | Deep Dive |
| CVE-2024-30447 | WordPress Creative Image Slider plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerability | Creative Solutions | Creative Image Slider – Responsive Slider Plugin | High | 7.1 | 2024-03-29 16:51:19 | Deep Dive |
| CVE-2015-10130 | WordPress Plugin Team Circle Image Slider With Lightbox 安全漏洞 | nik00726 | Team Circle Image Slider With Lightbox | Medium | 5.3 | 2024-03-13 02:34:52 | Deep Dive |
| CVE-2024-1859 | Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection | awordpresslife | Responsive Slideshow | High | 8.8 | 2024-03-01 06:47:51 | Deep Dive |
| CVE-2024-24931 | WordPress Before After Image Slider WP Plugin <= 2.2 is vulnerable to Cross Site Scripting (XSS) | swadeshswain | Before After Image Slider WP | Medium | 6.5 | 2024-02-12 05:52:26 | Deep Dive |