Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Huge-it Subscribe
Total 16 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-2062 2 Huge-it, Microsoft 2 Huge-it Slider, Windows 2020-02-10 6.5 MEDIUM 7.2 HIGH
Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to wp-admin/admin.php.
CVE-2016-11018 1 Huge-it 1 Image Gallery 2020-02-06 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
CVE-2016-1000113 1 Huge-it 1 Gallery 2019-12-19 7.5 HIGH 9.8 CRITICAL
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000114 1 Huge-it 1 Gallery 2019-12-19 4.3 MEDIUM 6.1 MEDIUM
XSS in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000118 1 Huge-it 1 Slideshow 2018-05-02 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000119 1 Huge-it 1 Catalog 2018-05-02 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000115 1 Huge-it 1 Portfolio Gallery Manager 2017-11-13 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000123 1 Huge-it 1 Video Gallery 2017-09-05 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CVE-2016-1000125 1 Huge-it 1 Huge-it Catalog 2017-09-05 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2017-09-05 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2016-1000116 1 Huge-it 1 Portfolio Gallery Manager 2017-03-27 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000117 1 Huge-it 1 Slideshow 2017-01-05 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000122 1 Huge-it 1 Slider 2016-12-22 6.5 MEDIUM 7.2 HIGH
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000120 1 Huge-it 1 Catalog 2016-12-22 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000121 1 Huge-it 1 Slider 2016-11-28 3.5 LOW 4.8 MEDIUM
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2014-7153 1 Huge-it 1 Image Gallery 2014-09-22 6.5 MEDIUM N/A
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.