Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Reflex Gallery Project Subscribe
Filtered by product Reflex Gallery
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-7482 1 Reflex Gallery Project 1 Reflex Gallery 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
CVE-2015-4133 1 Reflex Gallery Project 1 Reflex Gallery 2016-11-28 7.5 HIGH N/A
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.