Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High0
Medium5
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2026-04-15

CVE-2026-2479 - Responsive Lightbox Plugin

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host comparison in the `ajax_upload_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application, which can be used to query and modify information from internal services.

PLUGIN Responsive Lightbox

CVE-2026-2479

MEDIUM CVSS 5.0 2026-02-25
Threat Entry Updated 2025-11-19

CVE-2025-12359 - Responsive Lightbox Plugin

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.3 via the 'get_image_size_by_url' function. This is due to insufficient validation of user-supplied URLs when determining image dimensions for gallery items. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.

PLUGIN Responsive Lightbox

CVE-2025-12359

MEDIUM CVSS 5.4 2025-11-19
Threat Entry Updated 2025-07-01

CVE-2025-5093 - Responsive Lightbox Plugin

The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Responsive Lightbox

CVE-2025-5093

MEDIUM CVSS 5.4 2025-06-27
Threat Entry Updated 2025-06-04

CVE-2025-3742 - Responsive Lightbox Plugin

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Responsive Lightbox

CVE-2025-3742

MEDIUM CVSS 6.8 2025-05-15
Threat Entry Updated 2024-09-27

CVE-2024-6870 - Responsive Lightbox Plugin

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.

PLUGIN Responsive Lightbox

CVE-2024-6870

MEDIUM CVSS 6.4 2024-08-22
Scroll to top