Vulnerabilities > Enviragallery > Envira Gallery > 1.8.3.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-01 | CVE-2024-43925 | Missing Authorization vulnerability in Enviragallery Envira Gallery Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Photo Gallery: from n/a through 1.8.14. | 8.8 |
2024-09-11 | CVE-2024-3899 | Cross-site Scripting vulnerability in Enviragallery Envira Gallery The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks. | 4.8 |
2024-01-11 | CVE-2023-6742 | Improper Check for Unusual or Exceptional Conditions vulnerability in Enviragallery Envira Gallery The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. | 4.3 |
2022-10-31 | CVE-2022-2190 | Unspecified vulnerability in Enviragallery Envira Gallery The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | 6.1 |