
CVE-2024-13906 – Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection
https://notcve.org/view.php?id=CVE-2024-13906
06 Mar 2025 — The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin o... • https://plugins.trac.wordpress.org/browser/gallery-plugin/tags/4.7.3/gallery-plugin.php#L292 • CWE-502: Deserialization of Untrusted Data •

CVE-2025-26778 – WordPress Gallery Custom Links Plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2025-26778
14 Feb 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Gallery allows Stored XSS. This issue affects Gallery: from n/a through 2.2.1. The Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execu... • https://patchstack.com/database/wordpress/plugin/gallery/vulnerability/wordpress-gallery-custom-links-plugin-2-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-11501 – Gallery <= 1.3 - Authenticated (Contributor+) PHP Object Injection
https://notcve.org/view.php?id=CVE-2024-11501
06 Dec 2024 — The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted input from wd_gallery_$id parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retriev... • https://plugins.trac.wordpress.org/browser/multi-gallery/tags/1.3/partials/Shortcode.php#L21 • CWE-502: Deserialization of Untrusted Data •

CVE-2024-20827
https://notcve.org/view.php?id=CVE-2024-20827
06 Feb 2024 — Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen. Una vulnerabilidad de control de acceso inadecuado en Samsung Gallery anterior a la versión 14.5.04.4 permite a atacantes físicos acceder a la imagen usando el teclado físico en la pantalla de bloqueo. • https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02 •

CVE-2023-45630 – WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-45630
11 Oct 2023 — Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada No Autenticada en el complemento wpdevart Gallery – Image and Video Gallery with Thumbnails en versiones <= 2.0.3. The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output e... • https://patchstack.com/database/vulnerability/gallery-album/wordpress-gallery-image-and-video-gallery-with-thumbnails-plugin-2-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-30725
https://notcve.org/view.php?id=CVE-2023-30725
06 Sep 2023 — Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider. La autenticación incorrecta en LocalProvier of Gallery anterior a la versión 14.5.01.2 permite a un atacante acceder a los datos del proveedor de contenidos. • https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=09 • CWE-287: Improper Authentication •

CVE-2023-30724
https://notcve.org/view.php?id=CVE-2023-30724
06 Sep 2023 — Improper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search history. Una autenticación inadecuada en GallerySearchProvider de Gallery anterior a la versión 14.5.01.2 permite a los atacantes el acceso al historial de búsqueda. • https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=09 • CWE-287: Improper Authentication •

CVE-2023-0764 – Gallery by BestWebSoft < 4.7.0 - Author+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2023-0764
27 Mar 2023 — The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role. The Gallery by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via gallery information in versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi... • https://wpscan.com/vulnerability/d48c6c50-3734-4191-9833-0d9b09b1bd8a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-0765 – Gallery by BestWebSoft < 4.7.0 - Author+ SQL Injection
https://notcve.org/view.php?id=CVE-2023-0765
27 Mar 2023 — The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable. The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.6.9 due to insufficient escaping on t... • https://wpscan.com/vulnerability/2699cefa-1cae-4ef3-ad81-7f3db3fcce25 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-1946 – Gallery < 2.0.0 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-1946
13 Jun 2022 — The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue El plugin Gallery de WordPress versiones anteriores a 2.0.0, no sanea y escapa de un parámetro antes de devolverlo en la respuesta de una acción AJAX (disponible tanto para usuarios no autentificados como autentificados), conlleva un problema de tipo Cross-S... • https://wpscan.com/vulnerability/0903920c-be2e-4515-901f-87253eb30940 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •