Vulnerabilities > Ghozylab

DATE CVE VULNERABILITY TITLE RISK
2022-07-18 CVE-2022-2223 Cross-Site Request Forgery (CSRF) vulnerability in Ghozylab Image Slider
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider.
network
low complexity
ghozylab CWE-352
4.3
2022-07-18 CVE-2022-2224 Unspecified vulnerability in Ghozylab Gallery for Social Photo
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed.
network
low complexity
ghozylab
4.3
2015-09-28 CVE-2015-7386 Cross-site Scripting vulnerability in Ghozylab Gallery - Photo Albums - Portfolio 1.3.47
Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields.
network
ghozylab CWE-79
3.5