Inpost Gallery
Pluginus · 3 CVEs
CVE-2024-11002
MEDIUM
InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_…
Nov 26, 2024
CVE-2023-28666
MEDIUM
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability…
Mar 22, 2023
CVE-2022-4063
CRITICAL
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
Dec 19, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-11002 | InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template | MEDIUM | 0.59% | Nov 26, 2024 |
| CVE-2023-28666 | The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_in… | MEDIUM | 0.44% | Mar 22, 2023 |
| CVE-2022-4063 | InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE | CRITICAL | 9.62% | Dec 19, 2022 |
Showing 1 to 3 of 3 CVEs