Gallery Bank – WordPress Photo Gallery Plugin

Vulnerabilities 21Slug gallery-bankLatest version 4.0.50Plugin page →

Minimum safe version

4.0.19

Update to 4.0.19 or later to address 15 fixable vulnerabilities

Latest available4.0.50 Affected up to4.0.50 ⚠ 4 vulnerabilities have no fix
N/A
2023-07-19< 4.0.19

WordPress Gallery Bank Plugin <= 4.0.18 is vulnerable to Cross Site Scripting (XSS)

N/A
2013-10-28< 2.0.20

Gallery Bank – WordPress Photo Gallery Plugin < 2.0.20 - Reflected Cross-Site Scripting

N/A
2014-08-01< 3.0.229

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

N/A
2014-11-25< 3.0.61

Gallery Bank – WordPress Photo Gallery Plugin < 3.0.61 - Arbitrary File Upload

N/A
2015-02-21< 3.0.102

Gallery Bank – WordPress Photo Gallery <= 3.0.101 - SQL Injection

N/A
2015-08-21< 3.0.330

Gallery Bank – WordPress Photo Gallery Plugin <= 3.0.229 - SQL Injection

N/A Unfixed
2022-06-09≤ 4.0.50

Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 - Stored Cross-Site Scripting via Gallery Description

N/A Unfixed
2022-06-09≤ 4.0.50

Gallery Bank – WordPress Photo Gallery Plugin <= 4.0.50 - Stored Cross-Site Scripting via Media Upload

N/A
< 2.0.20

Gallery Bank 2.0.19 - Multiple Unspecified Issues

N/A
< 2.0.20

Gallery Bank 2.0.19 - edit-album.php album_id Parameter Reflected XSS

N/A
< 2.0.20

Gallery Bank 2.0.19 - album-gallery-bank-class.php recordsArray Parameter Reflected XSS

N/A
< 3.0.61

Gallery Bank &lt;= 3.0.60 - Shell Upload

N/A
< 3.0.102

Gallery Bank &lt;= 3.0.101 - SQL Injection

N/A
< 3.0.330

Gallery Bank &lt;= 3.0.229 - Authenticated Blind SQL Injection

N/A Unfixed Closed
≤ 4.0.50

Gallery Bank &lt;= 4.0.50 - Author+ Stored XSS via Media Upload Module

N/A Unfixed Closed
≤ 4.0.50

Gallery Bank &lt;= 4.0.50 - Author+ Stored XSS via Gallery Description

N/A
< 3.0.229

Multiple Plugins - jQuery prettyPhoto DOM Cross-Site Scripting (XSS)

N/A Closed
2015-05-14< 3.0.229

WordPress Gallery Bank Plugin <= 3.0.228 - Cross Site Scripting

N/A Closed
2022-06-09≤ 4.0.50

WordPress Gallery Bank plugin <= 4.0.50 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Gallery Description

N/A Closed
2022-06-09≤ 4.0.50

WordPress Gallery Bank plugin <= 4.0.50 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability via Media Upload Module