← WordPress Vulnerabilities
WordPress security by component

Slideshow Gallery LITE

Slideshow Gallery LITE is a WordPress component with 14 published CVE records in this archive. The latest tracked vulnerability was published Jun 18, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: slideshow-gallery

CVE-2026-2021: Slideshow Gallery LITE: Cross-site scripting

Slideshow Gallery LITE is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.5.

PublishedJun 18, 2026
Known safe version> 1.8.5
Safe version
Jun 18, 2026 CVE-2026-2021
Slideshow Gallery LITE: Cross-site scripting
Slideshow Gallery LITE is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.5.
> 1.8.5
CVE6.4
NVDPending
Oct 05, 2024 CVE-2024-47376
Slideshow Gallery: Cross-site scripting
Slideshow Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Jun 12, 2024 CVE-2024-5543
Slideshow Gallery LITE: SQL injection
Slideshow Gallery LITE is affected by SQL injection. Exploitation requires at least contributor-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.1
NVDPending
Apr 12, 2024 CVE-2024-31354
Slideshow Gallery: Cross-site request forgery
Slideshow Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Apr 10, 2024 CVE-2024-31355
Slideshow Gallery: SQL injection
Slideshow Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Apr 10, 2024 CVE-2024-31353
Slideshow Gallery: A security weakness
Slideshow Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Dec 20, 2023 CVE-2023-28491
Slideshow Gallery LITE: SQL injection
Slideshow Gallery LITE is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.7
NVD7.2
Nov 12, 2023 CVE-2023-28497
Slideshow Gallery: Cross-site request forgery
Slideshow Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Nov 23, 2021 CVE-2021-24882
Slideshow Gallery: Cross-site scripting
Slideshow Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Apr 15, 2019 CVE-2018-18019
Slideshow Gallery: Cross-site scripting
Slideshow Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 15, 2019 CVE-2018-18018
Slideshow Gallery: SQL injection
Slideshow Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Apr 15, 2019 CVE-2018-18017
Slideshow Gallery: Cross-site scripting
Slideshow Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 03, 2018 CVE-2018-17946
Slideshow Gallery: Cross-site scripting
Slideshow Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 11, 2014 CVE-2014-5460
Slideshow Gallery: A security weakness
Slideshow Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5