Anblik develops an image-gallery product suite with web-facing functionality, and its observed vulnerability footprint centers on application-layer input-handling weaknesses including SQL injection and cross-site scripting. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anblik over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1002015CRITICAL Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter. | Sep 14, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-1002014CRITICAL Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter. | Sep 14, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-1002013CRITICAL Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php. | Sep 14, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-1002012CRITICAL Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via t | Sep 14, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-1002011MEDIUM Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone | Sep 14, 2017 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anblik.
Media articles that mention a CVE ID that affects a product developed by Anblik — matched by CVE ID, not by vendor name.