Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
wp-video-gallery-free_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WP Video Gallery <= 1.7.1 - Unauthenticated SQLi

The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CWE-89May 9, 20221 related artifact
CVSS9.8v3.1EPSS9.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX