Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...
- CVSS:
- 6.5
- Affected:
- up to 1.8.41
- Fixed in:
- 1.8.42
- Disclosed:
- Jun 5, 2026
CVE-2026-9829 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 - Authenticated (Contributor+) SQL Injection
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attac...
- CVSS:
- 6.5
- Affected:
- up to 1.8.41
- Fixed in:
- 1.8.42
- Disclosed:
- Jun 4, 2026
CVE-2026-49771 on NVD →
Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...
- CVSS:
- 6.5
- Affected:
- up to 1.8.40
- Fixed in:
- 1.8.41
- Disclosed:
- May 27, 2026
CVE-2026-7048 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] <= 1.8.37 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37.
- Affected:
- up to 1.8.37
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-27360 on NVD →
Photo Gallery by 10Web <= 1.8.37 - Cross-Site Request Forgery
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.37. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 1.8.37
- Fixed in:
- 1.8.38
- Disclosed:
- Feb 8, 2026
CVE-2026-32330 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary ima...
- CVSS:
- 5.3
- Affected:
- up to 1.8.36
- Fixed in:
- 1.8.37
- Disclosed:
- Jan 21, 2026
CVE-2026-1036 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.38 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 1.8.38
- Fixed in:
- 1.8.39
- Disclosed:
- Dec 25, 2025
CVE-2026-27360 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘image_id’ parameter in all versions up to, and including, 1.8.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...
- CVSS:
- 6.1
- Affected:
- up to 1.8.34
- Fixed in:
- 1.8.35
- Disclosed:
- Apr 11, 2025
CVE-2025-2269 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.33
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.8.33
- Fixed in:
- 1.8.33
- Disclosed:
- Mar 24, 2025
CVE-2024-13124 on NVD →
Photo Gallery by 10Web <= 1.8.33 - Unauthenticated Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.8.33 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 1.8.33
- Fixed in:
- 1.8.34
- Disclosed:
- Mar 10, 2025
CVE-2025-0613 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.32 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Titles in all versions up to, and including, 1.8.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.8.32
- Fixed in:
- 1.8.33
- Disclosed:
- Mar 2, 2025
CVE-2024-13124 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.16
unknown
[en] Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through 1.8.15.
- Affected:
- up to 1.8.16
- Fixed in:
- 1.8.16
- Disclosed:
- Dec 13, 2024
CVE-2023-33995 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.31
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.8.31
- Fixed in:
- 1.8.31
- Disclosed:
- Nov 29, 2024
CVE-2024-10704 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.30 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Titles in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.8.30
- Fixed in:
- 1.8.31
- Disclosed:
- Nov 14, 2024
CVE-2024-10704 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.31
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administr...
- Affected:
- up to 1.8.31
- Fixed in:
- 1.8.31
- Disclosed:
- Nov 5, 2024
CVE-2024-9878 on NVD →
Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.8.30
- Fixed in:
- 1.8.31
- Disclosed:
- Nov 4, 2024
CVE-2024-9878 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.28
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.8.28
- Fixed in:
- 1.8.28
- Disclosed:
- Oct 9, 2024
CVE-2024-5968 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.28
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.27.
- Affected:
- up to 1.8.28
- Fixed in:
- 1.8.28
- Disclosed:
- Oct 6, 2024
CVE-2024-44043 on NVD →
Photo Gallery by 10Web <= 1.8.28 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.8.28
- Fixed in:
- 1.8.29
- Disclosed:
- Oct 3, 2024
CVE-2024-8670 on NVD →
Photo Gallery by 10Web <= 1.8.27 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts...
- CVSS:
- 4.4
- Affected:
- up to 1.8.27
- Fixed in:
- 1.8.28
- Disclosed:
- Sep 23, 2024
CVE-2024-44043 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.26
unknown
[en] Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
- Affected:
- up to 1.8.26
- Fixed in:
- 1.8.26
- Disclosed:
- Jun 11, 2024
CVE-2024-35628 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.24
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject...
- Affected:
- up to 1.8.24
- Fixed in:
- 1.8.24
- Disclosed:
- Jun 7, 2024
CVE-2024-5426 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.24
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste (copy) the contents of arbitrary files on the server, which can...
- Affected:
- up to 1.8.24
- Fixed in:
- 1.8.24
- Disclosed:
- Jun 7, 2024
CVE-2024-5481 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste (copy) the contents of arbitrary files on the server, which can conta...
- CVSS:
- 6.8
- Affected:
- up to 1.8.23
- Fixed in:
- 1.8.24
- Disclosed:
- Jun 6, 2024
CVE-2024-5481 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbit...
- CVSS:
- 6.4
- Affected:
- up to 1.8.23
- Fixed in:
- 1.8.24
- Disclosed:
- Jun 6, 2024
CVE-2024-5426 on NVD →
Photo Gallery by 10Web <= 1.8.25 - Missing Authorization to Notice Dismissal
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dismiss_notice function in all versions up to, and including, 1.8.25. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 1.8.25
- Fixed in:
- 1.8.26
- Disclosed:
- May 27, 2024
CVE-2024-35628 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.21
unknown
[en] Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.
- Affected:
- up to 1.8.21
- Fixed in:
- 1.8.21
- Disclosed:
- Apr 29, 2024
CVE-2024-33586 on NVD →
Photo Gallery by 10Web <= 1.8.20 - Missing Authorization
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.20. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.21
- Disclosed:
- Apr 25, 2024
CVE-2024-33586 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Reflected XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.21.
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Apr 18, 2024
CVE-2024-32583 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adminis...
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Apr 6, 2024
CVE-2024-2296 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato...
- CVSS:
- 5.5
- Affected:
- up to 1.8.21
- Fixed in:
- 1.8.22
- Disclosed:
- Apr 5, 2024
CVE-2024-2296 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'image_url'
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...
- CVSS:
- 6.1
- Affected:
- up to 1.8.21
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29809 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'current_url'
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_url' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 1.8.21
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29832 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'image_id'
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'image_id' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...
- CVSS:
- 6.1
- Affected:
- up to 1.8.21
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29808 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'thumb_url'
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...
- CVSS:
- 6.1
- Affected:
- up to 1.8.21
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29810 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_id parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must targe...
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29808 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must tar...
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29809 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must tar...
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29810 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the current_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. No authentication is...
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29832 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.22
unknown
[en] The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An attacker must target an authenticated u...
- Affected:
- up to 1.8.22
- Fixed in:
- 1.8.22
- Disclosed:
- Mar 26, 2024
CVE-2024-29833 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.20
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This makes it possible for authenticated attackers to rename arbitrary files on the server. This can lead to site takeovers...
- Affected:
- up to 1.8.20
- Fixed in:
- 1.8.20
- Disclosed:
- Feb 5, 2024
CVE-2024-0221 on NVD →
Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename
critical
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This makes it possible for authenticated attackers to rename arbitrary files on the server. This can lead to site takeovers if t...
- CVSS:
- 9.1
- Affected:
- up to 1.8.19
- Fixed in:
- 1.8.20
- Disclosed:
- Jan 19, 2024
CVE-2024-0221 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.19
unknown
[en] The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with administrator-level and a...
- Affected:
- up to 1.8.19
- Fixed in:
- 1.8.19
- Disclosed:
- Jan 11, 2024
CVE-2023-6924 on NVD →
Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with administrator-level and above...
- CVSS:
- 4.4
- Affected:
- up to 1.8.18
- Fixed in:
- 1.8.19
- Disclosed:
- Dec 21, 2023
CVE-2023-6924 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.69
unknown
[en] The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
- Disclosed:
- Jun 7, 2023
CVE-2021-46889 on NVD →
Photo Gallery <= 1.8.15 - Missing Authorization
medium
The Photo Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function called via an AJAX action in versions up to, and including, 1.8.15. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to chec...
- CVSS:
- 4.3
- Affected:
- up to 1.8.16
- Fixed in:
- 1.8.16
- Disclosed:
- Jun 2, 2023
CVE-2023-33995 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.16
unknown
The Photo Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function called via an AJAX action in versions up to, and including, 1.8.15. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to chec...
- Affected:
- up to 1.8.16
- Fixed in:
- 1.8.16
- Disclosed:
- Jun 2, 2023
Photo Gallery by 10Web <= 1.8.14 - Authenticated (Administrator+) Directory Traversal
medium
The Photo Gallery plugin by 10Web for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.8.14 via the dir parameter. This allows authenticated attackers with administrator-level permissions to upload files to arbitrary directories on the server.
- CVSS:
- 4.9
- Affected:
- up to 1.8.14
- Fixed in:
- 1.8.15
- Disclosed:
- Mar 21, 2023
CVE-2023-1427 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.15
unknown
The Photo Gallery plugin by 10Web for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.8.14 via the dir parameter. This allows authenticated attackers with administrator-level permissions to upload files to arbitrary directories on the server.
- Affected:
- up to 1.8.15
- Fixed in:
- 1.8.15
- Disclosed:
- Mar 21, 2023
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.3
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later on in another page, which could lead to Stored XSS issue when an attacker makes a logged in admin open a malicious URL or page under their control.
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.3
- Disclosed:
- Dec 19, 2022
CVE-2022-4058 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.69
unknown
[en] The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware information, previously connected to this CVE ID because of a t...
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
- Disclosed:
- Nov 29, 2022
CVE-2021-31693 on NVD →
Photo Gallery <= 1.8.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation one of its functions. This makes it possible for unauthenticated attackers to inject malicious JavaScript, that will execute whenever a user ac...
- CVSS:
- 6.1
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Nov 28, 2022
CVE-2022-4058 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.7 - Open Redirect
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to open redirect in versions up to 1.8.7. This is due to insufficient validation of the curr_url ($current_url) request parameter when a user accesses a link with an invalid share link. This would make it possible for an attacker to redirect a victim to a po...
- CVSS:
- 5.4
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Nov 26, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.8
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to open redirect in versions up to 1.8.7. This is due to insufficient validation of the curr_url ($current_url) request parameter when a user accesses a link with an invalid share link. This would make it possible for an attacker to redirect a victim to a po...
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Nov 26, 2022
Photo Gallery by 10Web <= 1.8.0 - Reflected Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘curr_url’ parameter in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 6.1
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 3, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.1
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘curr_url’ parameter in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 3, 2022
Photo Gallery <= 1.7.0 - Reflected Cross-Site Scripting
medium
The Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- Aug 10, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.7.1
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScan in WordPress Photo Gallery plugin (versions <= 1.7.0).
Update the WordPress Photo Gallery by 10Web plugin to the latest available version (at least 1.7.1).
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Aug 10, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.7.1
unknown
The Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Aug 10, 2022
Photo Gallery by 10Web <= 1.6.8 - Authenticated (Admin+) Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they ca...
- CVSS:
- 5.5
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.9
- Disclosed:
- Jul 1, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.9
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they ca...
- Affected:
- up to 1.6.9
- Fixed in:
- 1.6.9
- Disclosed:
- Jul 1, 2022
Photo Gallery by 10Web <= 1.6.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative privileges, to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.8
- Disclosed:
- Jun 28, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.8
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative privileges, to inject arbitrary web sc...
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jun 28, 2022
Photo Gallery by 10Web <= 1.6.6 - Reflected Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.6.6 . This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Jun 16, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.7
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.6.6 . This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- Jun 16, 2022
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.4
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Jun 6, 2022
CVE-2022-1394 on NVD →
Photo Gallery by 10Web <= 1.6.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Watermark font size" and "Watermark opacity" fields in versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administra...
- CVSS:
- 5.5
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- May 16, 2022
CVE-2022-1394 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.3
unknown
[en] The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- May 2, 2022
CVE-2022-1281 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.3
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- May 2, 2022
CVE-2022-1282 on NVD →
Photo Gallery by 10Web <= 1.6.2 - SQL Injection
high
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
- CVSS:
- 8.8
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Apr 11, 2022
CVE-2022-1281 on NVD →
Photo Gallery by 10Web <= 1.6.2 - Cross-Site Scripting
medium
The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.
- CVSS:
- 6.1
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Apr 11, 2022
CVE-2022-1282 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.6.0
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Mar 14, 2022
CVE-2022-0169 on NVD →
Photo Gallery by 10Web <= 1.5.87 - Unauthenticated SQL Injection via bwg_tag_id_bwg_thumbnails_0 Parameter
critical
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
- CVSS:
- 9.8
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Feb 15, 2022
CVE-2022-0169 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.68
unknown
[en] The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action
- Affected:
- up to 1.5.68
- Fixed in:
- 1.5.68
- Disclosed:
- Dec 6, 2021
CVE-2021-25041 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.77
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when ac...
- Affected:
- up to 1.5.77
- Fixed in:
- 1.5.77
- Disclosed:
- Aug 16, 2021
CVE-2021-24362 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.79
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector
- Affected:
- up to 1.5.79
- Fixed in:
- 1.5.79
- Disclosed:
- Aug 16, 2021
CVE-2021-24363 on NVD →
Photo Gallery by 10Web <= 1.5.78 - Stored Cross-Site Scripting via Uploaded SVG
medium
The Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.78 due to insufficient sanitization and escaping on SVG uploads. This makes it possible for low-level authenticated attackers, such as authors, to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 6.4
- Affected:
- up to 1.5.78
- Fixed in:
- 1.5.79
- Disclosed:
- Jul 19, 2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.79
unknown
The Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.78 due to insufficient sanitization and escaping on SVG uploads. This makes it possible for low-level authenticated attackers, such as authors, to inject arbitrary web scripts in pages that will exe...
- Affected:
- up to 1.5.79
- Fixed in:
- 1.5.79
- Disclosed:
- Jul 19, 2021
Photo Gallery <= 1.5.74 - Stored Cross-Site Scripting via Uploaded SVG
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessi...
- CVSS:
- 6.1
- Affected:
- up to 1.5.75
- Fixed in:
- 1.5.75
- Disclosed:
- Jul 18, 2021
CVE-2021-24362 on NVD →
Photo Gallery <= 1.5.74 - File Upload Path Traversal
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector
- CVSS:
- 4.9
- Affected:
- up to 1.5.75
- Fixed in:
- 1.5.75
- Disclosed:
- Jul 18, 2021
CVE-2021-24363 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.67
unknown
[en] The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashbo...
- Affected:
- up to 1.5.67
- Fixed in:
- 1.5.67
- Disclosed:
- Jun 1, 2021
CVE-2021-24310 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.74
unknown
Multiple Reflected Cross-Site Scripting (XSS) vulnerabilities discovered by m0ze and Thura Moe Myint in WordPress Photo Gallery by 10Web plugin (versions <= 1.5.73).
- Affected:
- up to 1.5.74
- Fixed in:
- 1.5.74
- Disclosed:
- May 19, 2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.69
unknown
[en] The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
- Disclosed:
- May 14, 2021
CVE-2021-24291 on NVD →
Photo Gallery <= 1.5.66 - Authenticated Stored Cross-Site Scripting via Gallery Title
medium
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard....
- CVSS:
- 4.8
- Affected:
- up to 1.5.67
- Fixed in:
- 1.5.67
- Disclosed:
- May 12, 2021
CVE-2021-24310 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.5.68 - Reflected Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'theme_id' parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 1.5.68
- Fixed in:
- 1.5.69
- Disclosed:
- Apr 19, 2021
CVE-2021-46889 on NVD →
Photo Gallery <= 1.5.68 - Multiple Reflected Cross-Site Scripting
medium
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)
- CVSS:
- 6.1
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
- Disclosed:
- Apr 19, 2021
CVE-2021-24291 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.5.68 - Reflected Cross-Site Scripting <= 1.5.68 - Reflected Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'album_gallery_id_0', 'bwg_album_search_0', and 'type_0' parameters in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta...
- CVSS:
- 6.1
- Affected:
- up to 1.5.68
- Fixed in:
- 1.5.69
- Disclosed:
- Apr 19, 2021
CVE-2021-31693 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.55
unknown
[en] Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
- Affected:
- up to 1.5.55
- Fixed in:
- 1.5.55
- Disclosed:
- Mar 18, 2021
CVE-2021-24139 on NVD →
Photo Gallery by 10Web <= 1.5.68 - Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ bwg_search_X’ parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 6.1
- Affected:
- up to 1.5.68
- Fixed in:
- 1.5.69
- Disclosed:
- Feb 23, 2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.69
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ bwg_search_X’ parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
- Disclosed:
- Feb 23, 2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.69
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Photo Gallery by 10Web plugin (versions <= 1.5.68).
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
- Disclosed:
- Feb 18, 2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.68
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Photo Gallery by 10Web plugin (versions <= 1.5.67).
- Affected:
- up to 1.5.68
- Fixed in:
- 1.5.68
- Disclosed:
- Feb 4, 2021
Photo Gallery <= 1.5.67 - Reflected Cross-Site Scripting
medium
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action
- CVSS:
- 6.1
- Affected:
- up to 1.5.68
- Fixed in:
- 1.5.68
- Disclosed:
- Feb 3, 2021
CVE-2021-25041 on NVD →
Photo Gallery by 10Web <= 1.5.54 - SQL Injection via bwg_search_x Parameter
critical
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.5.55
- Fixed in:
- 1.5.55
- Disclosed:
- May 15, 2020
CVE-2021-24139 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.55
unknown
Unauthenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien in WordPress Photo Gallery by 10Web plugin (versions <= 1.5.54).
- Affected:
- up to 1.5.55
- Fixed in:
- 1.5.55
- Disclosed:
- May 15, 2020
Photo Gallery by 10Web <= 1.5.45 - Multiple Cross-Site Scripting Issues
medium
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.
- CVSS:
- 5.5
- Affected:
- up to 1.5.45
- Fixed in:
- 1.5.46
- Disclosed:
- Feb 25, 2020
CVE-2020-9335 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.46
unknown
[en] Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.
- Affected:
- up to 1.5.46
- Fixed in:
- 1.5.46
- Disclosed:
- Feb 25, 2020
CVE-2020-9335 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.11
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipbo...
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Feb 8, 2020
CVE-2015-1394 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.35
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Photo Gallery by 10Web plugin (versions <= 1.5.34).
- Affected:
- up to 1.5.35
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 9, 2019
Photo Gallery by 10Web <= 1.5.34 - SQL Injection
critical
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.5.35
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 8, 2019
CVE-2019-16119 on NVD →
Photo Gallery by 10Web <= 1.5.34 - Cross-Site Scripting
medium
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
- CVSS:
- 6.1
- Affected:
- up to 1.5.34
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 8, 2019
CVE-2019-16118 on NVD →
Photo Gallery by 10Web <= 1.5.34 - Cross-Site Scripting
medium
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
- CVSS:
- 6.1
- Affected:
- up to 1.5.35
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 8, 2019
CVE-2019-16117 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.35
unknown
[en] Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
- Affected:
- up to 1.5.35
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 8, 2019
CVE-2019-16117 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.35
unknown
[en] Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
- Affected:
- up to 1.5.35
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 8, 2019
CVE-2019-16118 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.35
unknown
[en] SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
- Affected:
- up to 1.5.35
- Fixed in:
- 1.5.35
- Disclosed:
- Sep 8, 2019
CVE-2019-16119 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.42
unknown
[en] The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
- Affected:
- up to 1.2.42
- Fixed in:
- 1.2.42
- Disclosed:
- Aug 30, 2019
CVE-2015-9380 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.23
unknown
[en] The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
- Affected:
- up to 1.5.23
- Fixed in:
- 1.5.23
- Disclosed:
- Aug 9, 2019
CVE-2019-14797 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.25
unknown
[en] The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
- Affected:
- up to 1.5.25
- Fixed in:
- 1.5.25
- Disclosed:
- Aug 9, 2019
CVE-2019-14798 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.31
unknown
[en] A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
- Affected:
- up to 1.5.31
- Fixed in:
- 1.5.31
- Disclosed:
- Jul 30, 2019
CVE-2019-14313 on NVD →
Photo Gallery by 10Web <= 1.5.30 - SQL Injection
critical
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
- CVSS:
- 9.8
- Affected:
- up to 1.5.31
- Fixed in:
- 1.5.31
- Disclosed:
- Jul 26, 2019
CVE-2019-14313 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.31
unknown
SQL Injection (SQLi) vulnerability found by Tin Duong in WordPress Photo Gallery by 10Web plugin (versions <= 1.5.30).
- Affected:
- up to 1.5.31
- Fixed in:
- 1.5.31
- Disclosed:
- Jul 26, 2019
Photo Gallery by 10Web <= 1.5.24 - Authenticated Local File Inclusion
medium
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
- CVSS:
- 4.9
- Affected:
- up to 1.5.24
- Fixed in:
- 1.5.25
- Disclosed:
- May 15, 2019
CVE-2019-14798 on NVD →
Photo Gallery by 10Web <= 1.5.22 - Authenticated Cross-Site Scripting
medium
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
- CVSS:
- 5.4
- Affected:
- up to 1.5.22
- Fixed in:
- 1.5.23
- Disclosed:
- May 13, 2019
CVE-2019-14797 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.67
unknown
Cross-Site Scripting (XSS) vulnerability found in WordPress Photo Gallery by WD plugin (versions <=1.3.66).
- Affected:
- up to 1.3.67
- Fixed in:
- 1.3.67
- Disclosed:
- Feb 26, 2018
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.13
unknown
[en] Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Feb 19, 2018
CVE-2015-2324 on NVD →
Photo Gallery by 10Web <= 1.3.66 - Cross-Site Scripting
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.66 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.3.67
- Fixed in:
- 1.3.67
- Disclosed:
- Dec 14, 2017
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.67
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.66 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.3.67
- Fixed in:
- 1.3.67
- Disclosed:
- Dec 14, 2017
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.6
unknown
[en] Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Aug 28, 2017
CVE-2014-9312 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.51
unknown
[en] The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
- Affected:
- up to 1.3.51
- Fixed in:
- 1.3.51
- Disclosed:
- Aug 21, 2017
CVE-2017-12977 on NVD →
Photo Gallery by 10Web <= 1.3.50 - Authenticated SQL Injection via tag_id Parameter
high
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.3.51
- Fixed in:
- 1.3.51
- Disclosed:
- Aug 20, 2017
CVE-2017-12977 on NVD →
Photo Gallery by 10Web < 1.3.43 - Authenticated Path Traversal
medium
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.3.42. This allows administrative-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 4.1
- Affected:
- up to 1.3.43
- Fixed in:
- 1.3.43
- Disclosed:
- Jun 16, 2017
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.43
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.3.42. This allows administrative-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected:
- up to 1.3.43
- Fixed in:
- 1.3.43
- Disclosed:
- Jun 16, 2017
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.30
unknown
SQL injection vulnerability found in WordPress Web-Dorado Gallery plugin version 1.3.29 by DefenceCode
Update plugin to the latest possible version.
- Affected:
- up to 1.3.30
- Fixed in:
- 1.3.30
- Disclosed:
- May 5, 2017
Photo Gallery by 10Web <= 1.3.37 - Authenticated SQL Injection
high
The Photo Gallery by 10Web plugin for WordPress is vulnerable to SQL Injection via the ‘album_id’ parameter in versions up to, and including, 1.3.37 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacker...
- CVSS:
- 8.8
- Affected:
- up to 1.3.38
- Fixed in:
- 1.3.38
- Disclosed:
- May 2, 2017
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.38
unknown
The Photo Gallery by 10Web plugin for WordPress is vulnerable to SQL Injection via the ‘album_id’ parameter in versions up to, and including, 1.3.37 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacker...
- Affected:
- up to 1.3.38
- Fixed in:
- 1.3.38
- Disclosed:
- May 2, 2017
Photo Gallery by 10Web <= 1.2.12 - Authenticated Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Mar 13, 2015
CVE-2015-2324 on NVD →
Photo Gallery by 10Web <= 1.2.5 - Unrestricted File Upload
high
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
- CVSS:
- 8.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Feb 12, 2015
CVE-2014-9312 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.11
unknown
[en] SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Feb 2, 2015
CVE-2015-1393 on NVD →
Photo Gallery by 10Web <= 1.2.10 - Authenticated Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_d...
- CVSS:
- 5.4
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Jan 28, 2015
CVE-2015-1394 on NVD →
Photo Gallery by 10Web <= 1.2.10 - Authenticated SQL Injection via asc_or_desc Parameter
high
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
- CVSS:
- 8.8
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Jan 23, 2015
CVE-2015-1393 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.8
unknown
[en] SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Jan 16, 2015
CVE-2015-1055 on NVD →
Photo Gallery by 10Web <= 1.2.7 - Unauthenticated Blind SQL Injection via order_by Parameter
critical
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
- CVSS:
- 9.8
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Jan 12, 2015
CVE-2015-1055 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.1.31
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
- Affected:
- up to 1.1.31
- Fixed in:
- 1.1.31
- Disclosed:
- Oct 10, 2014
CVE-2014-6315 on NVD →
Photo Gallery by 10Web <= 1.1.30 - Reflected Cross-Site Scripting
low
Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.
- CVSS:
- 3.1
- Affected:
- up to 1.1.30
- Fixed in:
- 1.1.31
- Disclosed:
- Oct 1, 2014
CVE-2014-6315 on NVD →
Photo Gallery by 10Web <= 1.2.41 - Cross-Site Request Forgery
high
The Photo Gallery plugin before 1.2.42 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.2.42
- Fixed in:
- 1.2.42
- Disclosed:
- May 7, 2014
CVE-2015-9380 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.2.42
unknown
This plugin is prone to a cross site request forgery vulnerability.
Update the plugin.
- Affected:
- up to 1.2.42
- Fixed in:
- 1.2.42
- Disclosed:
- May 7, 2014
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.7.1
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.79
unknown
The plugin did not ensure that uploaded SVG files inside a Zipped archive added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/ph...
- Affected:
- up to 1.5.79
- Fixed in:
- 1.5.79
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.5.69
unknown
The plugin did not properly sanitise the bwg_search_X GET parameter, available in a frontend gallery when the Show Search Box setting is enabled (disabled by default), leading to a reflected Cross-Site Scripting issue
- Affected:
- up to 1.5.69
- Fixed in:
- 1.5.69
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.67
unknown
User input gets first escaped with esc_html() and then urldecoded. This leads to the possibility of reflected XSS with a double url encoded payload.
- Affected:
- up to 1.3.67
- Fixed in:
- 1.3.67
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.43
unknown
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin was affected by an Authenticated Path Traversal security vulnerability.
- Affected:
- up to 1.3.43
- Fixed in:
- 1.3.43
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.3.36
unknown
http://www.defensecode.com/advisories/DC-2017-02-011_WordPress_WebDorado_Gallery_Plugin_Advisory.pdf
- Affected:
- up to 1.3.36
- Fixed in:
- 1.3.36
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.29
unknown
- Affected:
- up to 1.8.29
- Fixed in:
- 1.8.29
CVE-2024-8670 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.35
unknown
- Affected:
- up to 1.8.35
- Fixed in:
- 1.8.35
CVE-2025-2269 on NVD →
Photo Gallery by 10Web – Mobile-Friendly Image Gallery [photo-gallery] < 1.8.34
unknown
- Affected:
- up to 1.8.34
- Fixed in:
- 1.8.34
CVE-2025-0613 on NVD →