| CVE-2024-55981 | WordPress Nabz Image Gallery plugin <= v1.00 - SQL Injection vulnerability | Nabajit Roy | Nabz Image Gallery | Critical | 9.3 | 2024-12-16 14:31:19 | Deep Dive |
| CVE-2023-25060 | WordPress Album and Image Gallery plus Lightbox plugin <= 1.6.2 - Broken Access Control vulnerability | WP OnlineSupport, Essential Plugin | Album and Image Gallery plus Lightbox | Medium | 5.3 | 2024-12-09 11:31:36 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-53744 | WordPress Elementor Image Gallery plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability | SkyBootstrap | Elementor Image Gallery Plugin | Medium | 6.5 | 2024-12-01 21:29:00 | Deep Dive |
| CVE-2024-10034 | Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.4.2 - Authenticated (Editor+) Stored Cross-Site Scripting | gallerycreator | Mixed Media Gallery Blocks | Medium | 5.5 | 2024-11-22 05:33:42 | Deep Dive |
| CVE-2024-51914 | WordPress drop in image slideshow gallery plugin <= 12.0 - Cross Site Scripting (XSS) vulnerability | gopiplus | drop in image slideshow gallery | Medium | 6.5 | 2024-11-19 16:31:00 | Deep Dive |
| CVE-2024-9878 | Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting | 10web | Photo Gallery by 10Web – Mobile-Friendly Image Gallery | Medium | 4.4 | 2024-11-05 09:30:59 | Deep Dive |
| CVE-2024-49632 | WordPress CWD 3D Image Gallery plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | Senthil Vel | CWD 3D Image Gallery | High | 7.1 | 2024-10-29 13:09:25 | Deep Dive |
| CVE-2024-49258 | WordPress Limb Gallery plugin <= 1.5.7 - Arbitrary File Download vulnerability | Limbcode | WordPress Gallery Plugin – Limb Image Gallery | Medium | 6.5 | 2024-10-16 13:45:18 | Deep Dive |
| CVE-2024-49260 | WordPress Limb Gallery plugin <= 1.5.7 - Arbitrary File Upload vulnerability | Limbcode | WordPress Gallery Plugin – Limb Image Gallery | Critical | 9.9 | 2024-10-16 13:38:04 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9776 | ImagePress - Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings | butterflymedia | ImagePress – Image Gallery | Medium | 4.4 | 2024-10-12 05:39:41 | Deep Dive |
| CVE-2024-9778 | ImagePress – Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update | butterflymedia | ImagePress – Image Gallery | Medium | 4.3 | 2024-10-12 05:39:39 | Deep Dive |
| CVE-2024-9824 | ImagePress - Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update | butterflymedia | ImagePress – Image Gallery | Medium | 4.3 | 2024-10-12 05:39:39 | Deep Dive |
| CVE-2024-8431 | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure | robosoft | Robo Gallery – Photo & Image Slider | Medium | 4.3 | 2024-10-08 11:34:19 | Deep Dive |
| CVE-2024-9025 | Sight – Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title | codesupplyco | Sight – Professional Image Gallery and Portfolio | Medium | 5.3 | 2024-09-26 08:29:46 | Deep Dive |
| CVE-2024-43152 | WordPress 3D FlipBook plugin <= 1.15.6 - Cross Site Scripting (XSS) vulnerability | iberezansky | 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery | Medium | 5.9 | 2024-08-12 22:09:41 | Deep Dive |
| CVE-2024-3896 | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title | robosoft | Robo Gallery – Photo & Image Slider | Medium | 6.4 | 2024-07-24 12:43:38 | Deep Dive |
| CVE-2024-37215 | WordPress Transition Slider – Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) vulnerability | creativeinteractivemedia | Transition Slider – Responsive Image Slider and Gallery | Medium | 5.9 | 2024-07-22 09:28:51 | Deep Dive |
| CVE-2024-3632 | Smart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF | Unknown | Smart Image Gallery | - | - | 2024-07-13 06:00:04 | Deep Dive |