VendorsdFactoryresponsive_lightboxany version
Vulnerabilities

dFactory Responsive Lightbox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-43924
WordPress Responsive Lightbox & Gallery plugin <= 2.4.7 - Broken Access Control vulnerability
Published 2024-10-23 · Analyzed
9.8EPSS 0.005
CVE-2025-3742
Responsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSS
Published 2025-05-15 · Analyzed
6.8EPSS 0.005
CVE-2024-6870
Responsive Lightbox & Gallery <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload
Published 2024-08-22 · Analyzed
6.4EPSS 0.003
CVE-2017-2243
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-07-07 · Modified
6.1EPSS 0.015
CVE-2023-49174
WordPress Responsive Lightbox Plugin <= 2.4.5 is vulnerable to Cross Site Scripting (XSS)
Published 2023-12-15 · Modified
5.9EPSS 0.004
CVE-2025-5093
Responsive Lightbox & Gallery < 2.5.2 - Contributor+ Stored XSS
Published 2025-06-27 · Analyzed
5.4EPSS 0.002