Ghozylab develops a focused line of WordPress plugins centered on forms, galleries, and image presentation, presenting a modest but readily accessible attack surface within the WordPress ecosystem. The vendor's vulnerabilities cluster around web-application input-handling weaknesses, principally cross-site scripting and cross-site request forgery flaws that arise from improper neutralization during page generation and insufficient request validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghozylab over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46230HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local Fi | Apr 24, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-26742MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This i | Mar 25, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-26882MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects P | Feb 25, 2025 | 6.5 | 18 | NO | NO |
CVE-2022-2224MEDIUM The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existen | Jul 18, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-2223MEDIUM The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce | Jul 18, 2022 | 4.3 | 18 | NO | NO |
CVE-2024-3236MEDIUM The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stor | Jun 17, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-5730MEDIUM The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stor | Jun 30, 2025 | 4.3 | 16 | NO | NO |
CVE-2024-32147MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issu | Apr 15, 2024 | 5.4 | 15 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users | Sep 28, 2015 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghozylab.
Media articles that mention a CVE ID that affects a product developed by Ghozylab — matched by CVE ID, not by vendor name.