← Back

Reflex Gallery

reflex_gallery

Vendor: Reflex Gallery Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Reflex Gallery Project
1Reflex Gallery
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
1Reflex Gallery Project
1Reflex Gallery
May 6, 2026
May 28, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP ex...Show more
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.Show less