Vulnerabilities > Ghozylab

DATE CVE VULNERABILITY TITLE RISK
2024-04-15 CVE-2024-32147 Unspecified vulnerability in Ghozylab Contact Form
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through 1.1.23.
network
low complexity
ghozylab
5.4
2022-07-18 CVE-2022-2223 Cross-Site Request Forgery (CSRF) vulnerability in Ghozylab Image Slider
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider.
network
low complexity
ghozylab CWE-352
4.3
2022-07-18 CVE-2022-2224 Unspecified vulnerability in Ghozylab Gallery for Social Photo
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed.
network
low complexity
ghozylab
4.3