Huge It develops a focused portfolio of WordPress gallery and portfolio plugins—including Catalog, Gallery, Image Gallery, and Portfolio Gallery Manager—that serve content management and display functions across web properties. The vendor's vulnerability footprint reflects the attack surface inherent to web-facing plugins that process and display user-supplied content. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Huge It over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1000125CRITICAL Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla | Oct 6, 2016 | 9.8 | 43 | NO | YES |
CVE-2016-1000123CRITICAL Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla | Oct 6, 2016 | 9.8 | 42 | NO | YES |
CVE-2016-1000124CRITICAL Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 | Oct 6, 2016 | 9.8 | 41 | NO | YES |
CVE-2016-1000113CRITICAL XSS and SQLi in huge IT gallery v1.1.5 for Joomla | Oct 6, 2016 | 9.8 | 31 | NO | NO |
CVE-2014-125101CRITICAL A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. I | May 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2016-11018CRITICAL An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The a | Jan 21, 2020 | 9.8 | 29 | NO | NO |
CVE-2016-1000122HIGH XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension | Oct 27, 2016 | 7.2 | 26 | NO | NO |
CVE-2014-7153MEDIUM SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execu | Sep 22, 2014 | 6.5 | 26 | NO | YES |
CVE-2016-1000120HIGH SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | Oct 27, 2016 | 7.2 | 25 | NO | NO |
CVE-2016-1000119HIGH SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | Oct 21, 2016 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Huge It.
Media articles that mention a CVE ID that affects a product developed by Huge It — matched by CVE ID, not by vendor name.