cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forphotoblocks-grid-gallery photoblocks-grid-gallery

Direction: ascending
Jun 07, 2024

Gallery PhotoBlocks # CVE-2019-15829

CVE, Research URL

CVE-2019-15829

Application

Gallery PhotoBlocks

Date
Aug 30, 2019
Research Description
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
Affected versions
max 1.1.43.
Status
vulnerable

Gallery PhotoBlocks # CVE-2022-37407

CVE, Research URL

CVE-2022-37407

Application

Gallery PhotoBlocks

Date
Sep 09, 2022
Research Description
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
Affected versions
max 1.2.7.
Status
vulnerable

Gallery PhotoBlocks # CVE-2022-36292

CVE, Research URL

CVE-2022-36292

Application

Gallery PhotoBlocks

Date
Aug 23, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
Affected versions
max 1.2.9.
Status
vulnerable
Nov 15, 2024

Gallery PhotoBlocks # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Application

Gallery PhotoBlocks

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.2.6.
Status
vulnerable
Sep 05, 2025

Gallery PhotoBlocks # CVE-2025-58610

CVE, Research URL

CVE-2025-58610

Application

Gallery PhotoBlocks

Date
Sep 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows Stored XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.1.
Affected versions
max 1.3.2.
Status
vulnerable
Jan 27, 2026

Gallery PhotoBlocks # CVE-2026-24389

CVE, Research URL

CVE-2026-24389

Application

Gallery PhotoBlocks

Date
Jan 22, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows DOM-Based XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.2.
Affected versions
max 1.3.3.
Status
vulnerable
Jun 16, 2026

Gallery PhotoBlocks # 9c464a1ba2ab5f94c0471cccd9243032c424be40

Application

Gallery PhotoBlocks

Date
Jul 05, 2019
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.41 WordPress Gallery Photoblocks plugin <= 1.1.40 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Gallery Photoblocks plugin (versions <= 1.1.40).
Affected versions
max 1.1.41.
Status
vulnerable

Gallery PhotoBlocks # 17211923e33c5fb97c001eac7bb85516d0da4ff0

Application

Gallery PhotoBlocks

Date
Jul 29, 2020
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.0 Gallery PhotoBlocks <= 1.1.5 - Cross-Site Scripting The Gallery PhotoBlocks plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.5 via several parameters due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 1.2.0.
Status
vulnerable

Gallery PhotoBlocks # 811416dc9e37c5314ae1e885f7f21dbd7389afa1

Application

Gallery PhotoBlocks

Date
Jul 05, 2019
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.41 Gallery Photoblocks <= 1.1.40 - Reflected Cross-Site Scripting The Gallery Photoblocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the GET 'id' parameter in versions up to, and including, 1.1.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.1.41.
Status
vulnerable

Gallery PhotoBlocks # a68496ed-67d3-4761-8f1f-d64424bec529

Application

Gallery PhotoBlocks

Date
-
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.0 Gallery PhotoBlocks &lt; 1.2.0 - Authenticated Cross-Site Scripting (XSS) The vulnerability is due to insufficient validation of gallery name parameter and image caption parameter. A remote attacker (any authenticated low privileged user) can exploit this to execute arbitrary script code within the context of the application.
Affected versions
max 1.2.0.
Status
vulnerable

Gallery PhotoBlocks # 8ac7de215e794d59ad6edfaaf75efeddefaa96b8

Application

Gallery PhotoBlocks

Date
Feb 28, 2022
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.6 WordPress Gallery PhotoBlocks plugin <= 1.2.4 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Gallery PhotoBlocks plugin (versions <= 1.2.4).
Affected versions
max 1.2.6.
Status
vulnerable

Gallery PhotoBlocks # e558cea6e723531a53e25ce9904cdc813839d85b

Application

Gallery PhotoBlocks

Date
Feb 28, 2022
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.6 WordPress Gallery PhotoBlocks plugin <= 1.2.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Gallery PhotoBlocks plugin (versions <= 1.2.4).
Affected versions
max 1.2.6.
Status
vulnerable

Gallery PhotoBlocks # 2aa811bbc4f4c73d078df9224626354e7a6f5529

Application

Gallery PhotoBlocks

Date
Jul 10, 2019
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.43 WordPress Gallery Photoblocks plugin <= 1.1.42 - Authenticated Cross-Site Scripting (XSS) vulnerability Authenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Gallery Photoblocks plugin (versions <= 1.1.42).
Affected versions
max 1.1.43.
Status
vulnerable

Gallery PhotoBlocks # 5c57e78a-97b9-4e23-8935-e4c9d806c89d

Application

Gallery PhotoBlocks

Date
-
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.41 Gallery Photoblocks &lt; 1.1.41 - Unauthenticated Reflected XSS Also Full Path Disclosure depending on the configuration of the server
Affected versions
max 1.1.41.
Status
vulnerable

Gallery PhotoBlocks # 49a2c22c842d21090919f915e007d58f37281c95

Application

Gallery PhotoBlocks

Date
Aug 17, 2022
Research Description
Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.9 Gallery PhotoBlocks <= 1.2.8 - Missing Authorization Checks The Gallery PhotoBlocks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.2.8 due to missing capability checks on the init() function found in the ~/admin/class-photoblocks-admin.php file. This makes it possible for authenticated users with minimal permissions, such as a subscriber, to delete and clone gallery photoblocks.
Affected versions
max 1.2.9.
Status
vulnerable
Jul 31, 2026

Gallery PhotoBlocks # CVE-2026-66448

CVE, Research URL

CVE-2026-66448

Application

Gallery PhotoBlocks

Date
Jul 27, 2026
Research Description
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
Affected versions
max 1.3.4.
Status
vulnerable
Sep 04, 2026

Gallery PhotoBlocks # CVE-2026-84781

CVE, Research URL

CVE-2026-84781

Application

Gallery PhotoBlocks

Date
Sep 02, 2026
Research Description
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
Affected versions
max 1.3.5.
Status
vulnerable