Skip to main content

Vendor/product archive

total-soft / video_gallery CVEs

Beta · best-effort

4 CVEs tagged to total-soft / video_gallery0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-9769

Published Dec 6, 2024

The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10247

Published Dec 6, 2024

The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and inclu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45069

Published Nov 6, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Pl…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-25979

Published May 3, 2023

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1