Filtered by vendor Galaxyweblinks Subscriptions
Filtered by product Gallery With Thumbnail Slider Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-5092 9 Famatehemes, Galaxyweblinks, Lightgalleryteam and 6 more 9 Onepress, Gallery With Thumbnail Slider, Lightgallery Wp and 6 more 2025-11-24 6.4 Medium
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2022-42485 1 Galaxyweblinks 1 Gallery With Thumbnail Slider 2025-01-10 5.4 Medium
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions.