Ghozylab
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Ghozylab product.
RSS Feeds for Ghozylab security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Ghozylab products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Ghozylab Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 2 vulnerabilities in Ghozylab with an average score of 6.5 out of ten. Last year, in 2025 Ghozylab had 8 security vulnerabilities published. Right now, Ghozylab is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.38
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 6.45 |
| 2025 | 8 | 6.83 |
| 2024 | 3 | 5.65 |
| 2023 | 0 | 0.00 |
| 2022 | 2 | 5.40 |
It may take a day or so for new Ghozylab vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Ghozylab Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-2422 | Sep 19, 2026 |
WP Composer 1.0.5 Stored XSS via pbwp_raw_shortcode Base64The WP Composer The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up to, and including, 1.0.5. This is due to the shortcode handler decoding Base64-encoded content and outputting it directly without any sanitization or escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Base64 encoding allows the payload to bypass WordPress's KSES content filtering at save time, since the encoded string contains no harmful HTML characters. |
|
| CVE-2025-68074 | Jun 26, 2026 |
Image Carousel <=1.0.0.41 XSS VulnerabilityContributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions. |
|
| CVE-2025-14446 | Dec 13, 2025 |
Easy Notify Lite WP: Auth Data Mod via Missing Capability (1.1.37)The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the easynotify_cp_reset() function in all versions up to, and including, 1.1.37. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset plugin settings to their default values. |
|
| CVE-2025-57966 | Sep 22, 2025 |
GhozyLab Gallery Lightbox 1.0.0.41 Stored XSSImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery Lightbox allows Stored XSS. This issue affects Gallery Lightbox: from n/a through 1.0.0.41. |
|
| CVE-2025-5730 | Jun 30, 2025 |
XSS in Contact Form Plugin WP before 1.1.29The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks. |
|
| CVE-2025-46230 | Apr 24, 2025 |
GhozyLab Popup Builder <=1.1.35 LFI via Include/RequireImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local File Inclusion.This issue affects Popup Builder: from n/a through <= 1.1.35. |
|
| CVE-2025-31586 | Mar 31, 2025 |
GhozyLab Gallery Photo Albums Plugin <=1.3.170 Stored XSSImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery Photo Albums Plugin easy-media-gallery allows Stored XSS.This issue affects Gallery Photo Albums Plugin: from n/a through <= 1.3.170. |
|
| CVE-2025-26742 | Mar 25, 2025 |
GhozyLab Gallery for Social Photo <=1.0.0.35 Stored XSSImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35. |
|
| CVE-2025-26882 | Feb 25, 2025 |
GhozyLab Popup Builder Stored XSS 1.1.33Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33. |
|
| CVE-2025-26962 | Feb 25, 2025 |
Easy Contact Form Lite <=1.1.25: XSS Stored in Input NeutralizationImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite contact-form-lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through <= 1.1.25. |
|
| CVE-2024-47623 | Oct 05, 2024 |
Gallery Lightbox Stored XSS v1.0.0.39 (Pre1.0.0.39)Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery Lightbox gallery-lightbox-slider allows Stored XSS.This issue affects Gallery Lightbox: from n/a through <= 1.0.0.39. |
|
| CVE-2024-3236 | Jun 17, 2024 |
XSS in Popup Builder WP Plugin Notification fields before 1.1.33The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks. |
|
| CVE-2024-32147 | Apr 15, 2024 |
Easy Contact Form Lite 1.1.23 Stored XSS via Input NeutralizationImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through 1.1.23. |
|
| CVE-2022-2224 | Jul 18, 2022 |
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up toThe WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link. |
|
| CVE-2022-2223 | Jul 18, 2022 |
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up toThe WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link. |
|