Slideshow Gallery
Vendor:
First CVE: Oct 3, 2018 · Active for 7 years
10
Total CVEs
More Total CVEs than 89% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Slideshow Gallery over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2018
7 years ago
Most Recent CVE
Apr 12, 2024
837 days ago
CVE Severity & Scoring
Slideshow Gallery10 CVEs
60%
30%
10%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (40.0%)
Unknown0 (0.0%)
Required6 (60.0%)
Privileges Required
Low1 (10.0%)
High2 (20.0%)
None7 (70.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18018CRITICAL SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] par | Apr 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2024-31355HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a thr | Apr 10, 2024 | 8.5 | 25 | NO | NO |
CVE-2023-28497HIGH Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions. | Nov 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-28491HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: fr | Dec 20, 2023 | 7.2 | 22 | NO | NO |
CVE-2018-18017MEDIUM XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | Apr 15, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-18019MEDIUM XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-slides&method=save Slide[title], Slide[media_file], or Slide[imag | Apr 15, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-17946MEDIUM The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter. | Oct 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2021-24882MEDIUM The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege user | Nov 23, 2021 | 4.8 | 18 | NO | NO |
CVE-2024-31354MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8. | Apr 12, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-31353MEDIUM Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8. | Apr 10, 2024 | 5.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Slideshow Gallery
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.8 | 3 | 7.3 | 1.4% | 0 | 0 |