VendorsReFlex Gallery Projectreflex_galleryany version
Vulnerabilities

ReFlex Gallery Project ReFlex Gallery any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-4133
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
Published 2015-05-28 · Modified
7.51 PoCEPSS 0.614
CVE-2013-7482
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
Published 2019-08-22 · Modified
6.1EPSS 0.009