Ghozylab Ghozylab

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Ghozylab product.

RSS Feeds for Ghozylab security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Ghozylab products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Ghozylab Sorted by Most Security Vulnerabilities since 2018

Ghozylab Contact Form2 vulnerabilities

Ghozylab Easy Notify Lite2 vulnerabilities

Ghozylab Image Carousel1 vulnerability

Ghozylab Image Slider1 vulnerability

Ghozylab Popup Builder1 vulnerability

By the Year

In 2026 there have been 2 vulnerabilities in Ghozylab with an average score of 6.5 out of ten. Last year, in 2025 Ghozylab had 8 security vulnerabilities published. Right now, Ghozylab is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.38




Year Vulnerabilities Average Score
2026 2 6.45
2025 8 6.83
2024 3 5.65
2023 0 0.00
2022 2 5.40

It may take a day or so for new Ghozylab vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Ghozylab Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-2422 Sep 19, 2026
WP Composer 1.0.5 Stored XSS via pbwp_raw_shortcode Base64 The WP Composer The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up to, and including, 1.0.5. This is due to the shortcode handler decoding Base64-encoded content and outputting it directly without any sanitization or escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The Base64 encoding allows the payload to bypass WordPress's KSES content filtering at save time, since the encoded string contains no harmful HTML characters.
CVE-2025-68074 Jun 26, 2026
Image Carousel <=1.0.0.41 XSS Vulnerability Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
Image Carousel
CVE-2025-14446 Dec 13, 2025
Easy Notify Lite WP: Auth Data Mod via Missing Capability (1.1.37) The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the easynotify_cp_reset() function in all versions up to, and including, 1.1.37. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset plugin settings to their default values.
CVE-2025-57966 Sep 22, 2025
GhozyLab Gallery Lightbox 1.0.0.41 Stored XSS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery Lightbox allows Stored XSS. This issue affects Gallery Lightbox: from n/a through 1.0.0.41.
CVE-2025-5730 Jun 30, 2025
XSS in Contact Form Plugin WP before 1.1.29 The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.
Contact Form
CVE-2025-46230 Apr 24, 2025
GhozyLab Popup Builder <=1.1.35 LFI via Include/Require Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local File Inclusion.This issue affects Popup Builder: from n/a through <= 1.1.35.
Easy Notify Lite
CVE-2025-31586 Mar 31, 2025
GhozyLab Gallery Photo Albums Plugin <=1.3.170 Stored XSS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery Photo Albums Plugin easy-media-gallery allows Stored XSS.This issue affects Gallery Photo Albums Plugin: from n/a through <= 1.3.170.
Easy Media Gallery
CVE-2025-26742 Mar 25, 2025
GhozyLab Gallery for Social Photo <=1.0.0.35 Stored XSS Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35.
Feed Instagram Lite
CVE-2025-26882 Feb 25, 2025
GhozyLab Popup Builder Stored XSS 1.1.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33.
Easy Notify Lite
CVE-2025-26962 Feb 25, 2025
Easy Contact Form Lite <=1.1.25: XSS Stored in Input Neutralization Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite contact-form-lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through <= 1.1.25.
Contact Form Lite
CVE-2024-47623 Oct 05, 2024
Gallery Lightbox Stored XSS v1.0.0.39 (Pre1.0.0.39) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery Lightbox gallery-lightbox-slider allows Stored XSS.This issue affects Gallery Lightbox: from n/a through <= 1.0.0.39.
Gallery Lightbox Slider
CVE-2024-3236 Jun 17, 2024
XSS in Popup Builder WP Plugin Notification fields before 1.1.33 The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.
Popup Builder
CVE-2024-32147 Apr 15, 2024
Easy Contact Form Lite 1.1.23 Stored XSS via Input Neutralization Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through 1.1.23.
Contact Form
CVE-2022-2224 Jul 18, 2022
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link.
Gallery For Social Photo
CVE-2022-2223 Jul 18, 2022
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link.
Image Slider
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.