dFactory records
9 published records for vendor dfactory.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-862 Missing Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-43924No exploit | WordPress Responsive Lightbox & Gallery plugin <= 2.4.7 - Broken Access Control vulnerabilitydfactory · responsive lightbox · CWE-862 | Critical9.8 | — | 0.5% | Oct 23, 2024 |
35Monitor | CVE-2024-31252No exploit | WordPress Responsive Lightbox & Gallery plugin <= 2.4.6 - Broken Access Control vulnerabilitydfactory · responsive lightbox \& gallery · CWE-862 | High8.8 | — | 0.4% | Jun 9, 2024 |
27Monitor | CVE-2025-3742No exploit | Responsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSSdfactory · responsive lightbox · CWE-79 | Medium6.8 | — | 0.5% | May 15, 2025 |
24Monitor | CVE-2017-2243No exploit | Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML vdfactory · responsive lightbox · CWE-79 | Medium6.1 | — | 1.5% | Jul 7, 2017 |
21Monitor | CVE-2023-0076No exploit | Download Attachments < 1.3 - Contributor+ Stored XSSdfactory · download attachments · CWE-79 | Medium5.4 | — | 0.5% | Mar 6, 2023 |
21Monitor | CVE-2023-49174No exploit | WordPress Responsive Lightbox Plugin <= 2.4.5 is vulnerable to Cross Site Scripting (XSS)dfactory · responsive lightbox · CWE-79 | Medium5.4 | — | 0.4% | Dec 15, 2023 |
21Monitor | CVE-2024-6870No exploit | Responsive Lightbox & Gallery <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via File Uploaddfactory · responsive lightbox · CWE-79 | Medium5.4 | — | 0.3% | Aug 22, 2024 |
21Monitor | CVE-2025-5093No exploit | Responsive Lightbox & Gallery < 2.5.2 - Contributor+ Stored XSSdfactory · responsive lightbox · CWE-79 | Medium5.4 | — | 0.2% | Jun 27, 2025 |
19Monitor | CVE-2021-24613No exploit | Post Views Counter < 1.3.5 - Authenticated Stored XSSdfactory · post views counter · CWE-79 | Medium4.8 | — | 0.6% | Sep 20, 2021 |
- CVE-2024-4392439Monitor
WordPress Responsive Lightbox & Gallery plugin <= 2.4.7 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 1%dfactory · responsive lightboxOct 23, 2024
- CVE-2024-3125235Monitor
WordPress Responsive Lightbox & Gallery plugin <= 2.4.6 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%dfactory · responsive lightbox \& galleryJun 9, 2024
- CVE-2025-374227Monitor
Responsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSS
MediumCVSS 6.8No exploitEPSS 1%dfactory · responsive lightboxMay 15, 2025
- CVE-2017-224324Monitor
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML v
MediumCVSS 6.1No exploitEPSS 1%dfactory · responsive lightboxJul 7, 2017
- CVE-2023-007621Monitor
Download Attachments < 1.3 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%dfactory · download attachmentsMar 6, 2023
- CVE-2023-4917421Monitor
WordPress Responsive Lightbox Plugin <= 2.4.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%dfactory · responsive lightboxDec 15, 2023
- CVE-2024-687021Monitor
Responsive Lightbox & Gallery <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload
MediumCVSS 5.4No exploitEPSS 0%dfactory · responsive lightboxAug 22, 2024
- CVE-2025-509321Monitor
Responsive Lightbox & Gallery < 2.5.2 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%dfactory · responsive lightboxJun 27, 2025
- CVE-2021-2461319Monitor
Post Views Counter < 1.3.5 - Authenticated Stored XSS
MediumCVSS 4.8No exploitEPSS 1%dfactory · post views counterSep 20, 2021