Known Vulnerabilities for All-in-one Video Gallery by Plugins360
Listed below are 2 of the newest known vulnerabilities associated with "All-in-one Video Gallery" by "Plugins360".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-88867 json | WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site sc... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-59256 json | WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without bi... | Not Provided | 2026-08-22 | 2026-08-26 |
| CVE-2026-50183 json | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in ... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-50182 json | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability t... | Not Provided | 2026-07-15 | 2026-07-17 |
| CVE-2026-19075 json | All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl= |
Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-18400 json | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored C... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-12123 json | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-10104 json | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbn... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2022-2633 json | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request for... | 8.2 - HIGH | 2022-09-06 | 2024-01-11 |
| CVE-2021-24970 json | The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it i... | 7.2 - HIGH | 2021-12-13 | 2021-12-16 |