VendorsTribulantslideshow_galleryall versions
Vulnerabilities

Tribulant Slideshow Gallery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2018-18018
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
Published 2019-04-15 · Modified
9.8EPSS 0.022
CVE-2023-28497
WordPress Slideshow Gallery Plugin <= 1.7.6 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-12 · Modified
8.8EPSS 0.003
CVE-2023-28491
WordPress Slideshow Gallery Plugin <= 1.7.6 is vulnerable to SQL Injection
Published 2023-12-20 · Modified
7.2EPSS 0.008
CVE-2018-18017
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
Published 2019-04-15 · Modified
6.1EPSS 0.010
CVE-2018-18019
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[image_url] parameter.
Published 2019-04-15 · Modified
6.1EPSS 0.010
CVE-2018-17946
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
Published 2018-10-03 · Modified
6.1EPSS 0.008
CVE-2024-31353
WordPress Slideshow Gallery LITE plugin <= 1.7.8 - Sensitive Data Exposure vulnerability
Published 2024-04-10 · Modified
5.3EPSS 0.005
CVE-2021-24882
Slideshow Gallery < 1.7.4 - Admin+ Stored Cross-Site Scripting
Published 2021-11-23 · Modified
4.8EPSS 0.006