Vulnerabilities (CVE)

Filtered by vendor Awplife Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24529 1 Awplife 1 Grid Gallery 2024-11-21 3.5 LOW 5.4 MEDIUM
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
CVE-2019-17072 1 Awplife 1 Contact Form Widget 2024-11-21 7.5 HIGH 9.8 CRITICAL
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.