Filtered by vendor Huge-it
Subscribe
Total
16 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-2062 | 2 Huge-it, Microsoft | 2 Huge-it Slider, Windows | 2020-02-10 | 6.5 MEDIUM | 7.2 HIGH |
Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to wp-admin/admin.php. | |||||
CVE-2016-11018 | 1 Huge-it | 1 Image Gallery | 2020-02-06 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback(). | |||||
CVE-2016-1000113 | 1 Huge-it | 1 Gallery | 2019-12-19 | 7.5 HIGH | 9.8 CRITICAL |
XSS and SQLi in huge IT gallery v1.1.5 for Joomla | |||||
CVE-2016-1000114 | 1 Huge-it | 1 Gallery | 2019-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS in huge IT gallery v1.1.5 for Joomla | |||||
CVE-2016-1000118 | 1 Huge-it | 1 Slideshow | 2018-05-02 | 6.5 MEDIUM | 7.2 HIGH |
XSS & SQLi in HugeIT slideshow v1.0.4 | |||||
CVE-2016-1000119 | 1 Huge-it | 1 Catalog | 2018-05-02 | 6.5 MEDIUM | 7.2 HIGH |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | |||||
CVE-2016-1000115 | 1 Huge-it | 1 Portfolio Gallery Manager | 2017-11-13 | 6.5 MEDIUM | 7.2 HIGH |
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | |||||
CVE-2016-1000123 | 1 Huge-it | 1 Video Gallery | 2017-09-05 | 7.5 HIGH | 9.8 CRITICAL |
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla | |||||
CVE-2016-1000125 | 1 Huge-it | 1 Huge-it Catalog | 2017-09-05 | 7.5 HIGH | 9.8 CRITICAL |
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla | |||||
CVE-2016-1000124 | 1 Huge-it | 1 Portfolio Gallery | 2017-09-05 | 7.5 HIGH | 9.8 CRITICAL |
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 | |||||
CVE-2016-1000116 | 1 Huge-it | 1 Portfolio Gallery Manager | 2017-03-27 | 6.5 MEDIUM | 7.2 HIGH |
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS | |||||
CVE-2016-1000117 | 1 Huge-it | 1 Slideshow | 2017-01-05 | 6.5 MEDIUM | 7.2 HIGH |
XSS & SQLi in HugeIT slideshow v1.0.4 | |||||
CVE-2016-1000122 | 1 Huge-it | 1 Slider | 2016-12-22 | 6.5 MEDIUM | 7.2 HIGH |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension | |||||
CVE-2016-1000120 | 1 Huge-it | 1 Catalog | 2016-12-22 | 6.5 MEDIUM | 7.2 HIGH |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | |||||
CVE-2016-1000121 | 1 Huge-it | 1 Slider | 2016-11-28 | 3.5 LOW | 4.8 MEDIUM |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension | |||||
CVE-2014-7153 | 1 Huge-it | 1 Image Gallery | 2014-09-22 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php. |