cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgallery-by-supsystic gallery-by-supsystic

Direction: ascending
Jun 07, 2024

Photo Gallery by Supsystic # CVE-2016-10918

CVE, Research URL

CVE-2016-10918

Date
Aug 22, 2019
Research Description
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
Affected versions
max 1.8.6.
Status
vulnerable

Photo Gallery by Supsystic # CVE-2024-29921

CVE, Research URL

CVE-2024-29921

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Supsystic: from n/a through <= 1.15.16.
Affected versions
max 1.15.17.
Status
vulnerable

Photo Gallery by Supsystic # CVE-2021-36891

CVE, Research URL

CVE-2021-36891

Date
Jun 16, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
Affected versions
max 1.15.6.
Status
vulnerable
Jun 16, 2026

Photo Gallery by Supsystic # 05ed5f05f8bcff08196048d060d89af66d2b04a2

Date
Aug 15, 2016
Research Description
Photo Gallery &#8211; Responsive Image Galleries by Supsystic [gallery-by-supsystic] < 1.8.6 WordPress Photo Gallery by Supsystic plugin <= 1.8.5 - Cross Site Request Forgery (CSRF) Because of this vulnerability, the attackers can add images to a gallery. Update the plugin.
Affected versions
max 1.8.6.
Status
vulnerable

Photo Gallery by Supsystic # 5c7f0255d07464a5a2c6e321fcd72a4b452d33d9

Date
Aug 14, 2016
Research Description
Photo Gallery &#8211; Responsive Image Galleries by Supsystic [gallery-by-supsystic] < 1.8.6 WordPress Photo Gallery by Supsystic plugin <= 1.8.5 - Cross Site Scripting (XSS) Because of this vulnerability, the attackers can steal users' session tokens or perform arbitrary actions on their behalf. Update the plugin.
Affected versions
max 1.8.6.
Status
vulnerable

Photo Gallery by Supsystic # a95c0025b812d7e4a02d946516dcb76d9514e76b

Date
Nov 11, 2014
Research Description
Photo Gallery &#8211; Responsive Image Galleries by Supsystic [gallery-by-supsystic] < 1.2.6 WordPress Photo Gallery by Supsystic plugin <=1.2.5 - Unrestricted File Upload WordPress Photo Gallery by Supsystic plugin unrestricted file upload vulnerability allows an access to upload functionality via "UploadHandler.php". Update to version 1.2.6.
Affected versions
max 1.2.6.
Status
vulnerable

Photo Gallery by Supsystic # be45d5b6-0a38-4bb9-9680-ee3a1edfcaee

Date
-
Research Description
Photo Gallery &#8211; Responsive Image Galleries by Supsystic [gallery-by-supsystic] < 1.8.6 Photo Gallery by Supsystic &lt; 1.8.6 - Stored Cross-Site Scripting via CSRF The plugin does not have CSRF check in place and it lacking sanitisation as well as escaping via in AJAX action to update attachment, which could lead to Stored XSS via CSRF
Affected versions
max 1.8.6.
Status
vulnerable
Jul 29, 2026

Photo Gallery by Supsystic # CVE-2026-24628

CVE, Research URL

CVE-2026-24628

Date
Jul 23, 2026
Research Description
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
Affected versions
max 1.16.3.
Status
vulnerable