Vulnerabilities > Photospace Gallery Project

DATE CVE VULNERABILITY TITLE RISK
2022-11-29 CVE-2022-3991 Cross-site Scripting vulnerability in Photospace Gallery Project Photospace Gallery 2.3.5
The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters saved via the update() function in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping.
network
low complexity
photospace-gallery-project CWE-79
5.4
2022-09-12 CVE-2022-38135 Unspecified vulnerability in Photospace Gallery Project Photospace Gallery 2.3.5
Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings.
network
low complexity
photospace-gallery-project
4.3