Unitegallery develops a lightweight gallery and media-display widget for web pages, with a focused exposure footprint concentrated in its Unite Gallery Lite product. The recurring vulnerability signal reflects classic web-application input-handling weaknesses, including cross-site scripting, SQL injection, and cross-site request forgery, typical of client-side and server-side rendering components that process untrusted user input and state. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unitegallery over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9445HIGH The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation. | Sep 26, 2019 | 8.8 | 23 | NO | NO |
CVE-2015-9446HIGH The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php. | Sep 26, 2019 | 8.8 | 22 | NO | NO |
CVE-2023-34183MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Valiano Unite Gallery Lite plugin <= 1.7.61 versions. | Aug 30, 2023 | 4.8 | 17 | NO | NO |
CVE-2015-9447MEDIUM The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters. | Sep 26, 2019 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unitegallery.
Media articles that mention a CVE ID that affects a product developed by Unitegallery — matched by CVE ID, not by vendor name.