VendorsEnvira Galleryenvira_galleryall versions
Vulnerabilities

Envira Gallery Envira Gallery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-43925
WordPress Envira Gallery Lite plugin <= 1.8.14 - Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
8.8EPSS 0.005
CVE-2022-2190
Envira Gallery Lite < 1.8.4.7 - Reflected Cross-Site Scripting
Published 2022-10-31 · Modified
6.1EPSS 0.006
CVE-2020-35581
A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php request with the meta[title] parameter.
Published 2021-01-15 · Modified
5.4EPSS 0.013
CVE-2020-35582
A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php request with the post_title parameter.
Published 2021-01-15 · Modified
5.4EPSS 0.013
CVE-2020-9334
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
Published 2020-02-25 · Modified
5.4EPSS 0.008
CVE-2021-24126
Envira Gallery Lite < 1.8.3.3 - Authenticated Stored Cross-Site Scripting
Published 2021-03-18 · Modified
5.4EPSS 0.007
CVE-2024-3899
Envira Gallery < 1.8.15 - Author+ Stored XSS
Published 2024-09-11 · Analyzed
4.8EPSS 0.004
CVE-2023-6742
Envira Gallery Lite <= 1.8.7.2 - Missing Authorization to Gallery Modification via envira_gallery_insert_images
Published 2024-01-11 · Modified
4.3EPSS 0.004