Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total6
Critical0
High0
Medium6
Reset
Showing 1-6 of 6 records
Threat Entry Updated 2026-01-26

CVE-2025-15466 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to view, create, modify, clone, delete, and reassign ownership of galleries created by other users, including administrators.

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2025-15466

MEDIUM CVSS 5.4 2026-01-20
Threat Entry Updated 2025-12-23

CVE-2025-13693 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2025-13693

MEDIUM CVSS 6.4 2025-12-21
Threat Entry Updated 2025-12-19

CVE-2025-14455 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to perform actions on gallery management functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete, modify, or clone galleries created by any user, including administrators.

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2025-14455

MEDIUM CVSS 5.4 2025-12-19
Threat Entry Updated 2025-03-11

CVE-2024-6261 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'FinalTilesGallery' shortcode in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2024-6261

MEDIUM CVSS 6.4 2025-02-27
Threat Entry Updated 2025-05-13

CVE-2024-3710 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2024-3710

MEDIUM CVSS 6.8 2024-07-13
Threat Entry Updated 2024-11-21

CVE-2022-0186 - Image Photo Gallery Final Tiles Grid Plugin

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

PLUGIN Image Photo Gallery Final Tiles Grid

CVE-2022-0186

MEDIUM CVSS 5.4 2022-02-21
Scroll to top