Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

All-in-One Video Gallery — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in All-in-One Video Gallery, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the vendor All-in-One Video Gallery, categorized under software vulnerability aggregates. It compiles a comprehensive collection of security flaws, ranging from critical remote code execution risks to minor information disclosure issues, covering advisory data released between 2018 and 2023. Visitors can utilize this resource to track specific vendor advisories, monitor the evolution of known weaknesses within this software category, and review the historical timeline of disclosed vulnerabilities for the product. The information is structured to help security professionals and system administrators understand the threat landscape, assess the severity of past incidents, and prioritize patching efforts based on verified vendor responses and public exploitability metrics. By aggregating these entries, the page serves as a centralized reference for evaluating the long-term security posture of All-in-One Video Gallery installations and identifying recurring patterns in code quality or configuration errors.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-19075 All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter - - 2026-08-10
CVE-2026-12123 All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter CWE-918 6.4 Medium 2026-07-10
CVE-2026-1706 All-in-One Video Gallery <= 4.7.1 - Reflected Cross-Site Scripting via 'vi' Parameter CWE-79 6.1 Medium 2026-03-04
CVE-2025-15516 All-in-One Video Gallery 4.1.0 - 4.6.4 - Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update CWE-862 4.3 Medium 2026-01-24
CVE-2025-14947 All-in-One Video Gallery <= 4.6.4 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion CWE-862 6.5 Medium 2026-01-23
CVE-2025-12957 All-in-One Video Gallery <= 4.5.7 - Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass CWE-434 8.8 High 2026-01-16
CVE-2025-12966 All-in-One Video Gallery 4.5.4 - 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import ZIP CWE-434 8.8 High 2025-12-06
CVE-2024-6629 All-in-One Video Gallery <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode CWE-79 6.4 Medium 2024-07-24
CVE-2024-31248 WordPress All-in-One Video Gallery plugin <= 3.5.2 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-06-09
CVE-2024-4670 All-in-One Video Gallery <= 3.6.5 - Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode CWE-98 8.8 High 2024-05-15
CVE-2024-4033 All-in-One Video Gallery <= 3.6.4 - Authenticated (Contributor+) Arbitrary File Upload via featured image CWE-434 8.8 High 2024-05-02
CVE-2022-2633 WordPress plugin All-in-One Video Gallery 安全漏洞 7.5 High 2022-09-06
CVE-2021-24970 All-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusion CWE-22 7.2 - 2021-12-13

All 13 known CVE vulnerabilities affecting All-in-One Video Gallery with full Chinese analysis, references, and POCs where available.