Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Powerplay Gallery Project Subscribe
Filtered by product Powerplay Gallery
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-5599 1 Powerplay Gallery Project 1 Powerplay Gallery 2019-07-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.
CVE-2015-5682 1 Powerplay Gallery Project 1 Powerplay Gallery 2017-06-08 5.0 MEDIUM 7.5 HIGH
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.