Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Gallery – Image and Video Gallery with Thumbnails | 2.0.0 ~ 2.0.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Gallery plugin before 2.0.0 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back in the response of an AJAX action, available to both unauthenticated and authenticated users. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1946.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-2268 | WP All Import < 3.6.8 - Admin+ Arbitrary File Upload | |
| CVE-2022-1967 | WP Championship < 9.3 - Multiple CSRF | |
| CVE-2022-1301 | WP Contact Slider < 2.4.7 - Editor+ Stored Cross-Site Scripting | |
| CVE-2022-0250 | Redirection for Contact Form 7 < 2.5.0 - Reflected Cross-Site Scripting | |
| CVE-2021-25066 | Ninja Forms < 3.6.10 - Admin+ Stored Cross-Site Scripting via Import | |
| CVE-2021-25056 | Ninja Forms < 3.6.10 - Admin+ Stored Cross-Site Scripting |
No comments yet