Vendors10Webphoto_galleryany version
Vulnerabilities

10Web Photo Gallery any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2019-14313
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
Published 2019-07-30 · Modified
10.0EPSS 0.045
CVE-2022-0169
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
Published 2022-03-14 · Modified
9.8EPSS 0.746
CVE-2022-1281
Photo Gallery < 1.6.3 - Unauthenticated SQL Injection
Published 2022-05-02 · Modified
9.8EPSS 0.431
CVE-2019-16119
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
Published 2019-09-08 · Modified
9.81 PoCEPSS 0.248
CVE-2021-24139
Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
Published 2021-03-18 · Modified
9.8EPSS 0.055
CVE-2024-0221
Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename
Published 2024-02-05 · Modified
9.1EPSS 0.013
CVE-2015-9380
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
Published 2019-08-30 · Modified
8.8EPSS 0.008
CVE-2024-5481
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function
Published 2024-06-07 · Modified
8.8EPSS 0.007
CVE-2017-12977
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
Published 2017-08-21 · Modified
7.2EPSS 0.016
CVE-2024-32583
WordPress Photo Gallery by 10Web plugin <= 1.8.21 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-04-18 · Modified
7.1EPSS 0.003
CVE-2015-1393
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
Published 2015-02-02 · Modified
6.5EPSS 0.017
CVE-2024-5426
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG
Published 2024-06-07 · Modified
6.4EPSS 0.003
CVE-2021-24291
Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)
Published 2021-05-14 · Modified
6.1EPSS 0.145
CVE-2019-16118
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
Published 2019-09-08 · Modified
6.11 PoCEPSS 0.053
CVE-2019-16117
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
Published 2019-09-08 · Modified
6.11 PoCEPSS 0.046
CVE-2021-25041
Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)
Published 2021-12-06 · Modified
6.1EPSS 0.009
CVE-2022-1282
Photo Gallery < 1.6.3 - Reflected Cross-Site Scripting
Published 2022-05-02 · Modified
6.1EPSS 0.009
CVE-2021-24362
Photo Gallery < 1.5.75 - Stored Cross-Site Scripting via Uploaded SVG
Published 2021-08-16 · Modified
6.1EPSS 0.008
CVE-2021-46889
The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.
Published 2023-06-07 · Modified
6.1EPSS 0.006
CVE-2024-29832
WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url
Published 2024-03-26 · Analyzed
6.1EPSS 0.004
CVE-2021-31693
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware information, previously connected to this CVE ID because of a typo, is at CVE-2022-31693.
Published 2022-11-29 · Analyzed
6.1EPSS 0.004
CVE-2025-0613
Photo Gallery < 1.8.34 - Unauthenticated Stored XSS
Published 2025-03-31 · Analyzed
6.1EPSS 0.003
CVE-2024-44043
WordPress Photo Gallery by 10Web plugin <= 1.8.27 - Cross Site Scripting (XSS) vulnerability
Published 2024-10-06 · Modified
5.9EPSS 0.003
CVE-2024-2296
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG
Published 2024-04-06 · Modified
5.5EPSS 0.004
CVE-2015-1394
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.
Published 2020-02-08 · Modified
5.4EPSS 0.023
CVE-2019-14797
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
Published 2019-08-09 · Modified
5.4EPSS 0.013
CVE-2015-2324
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
Published 2018-02-19 · Modified
5.4EPSS 0.009
CVE-2024-29833
WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler
Published 2024-03-26 · Analyzed
5.4EPSS 0.004
CVE-2024-29810
WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url
Published 2024-03-26 · Analyzed
5.4EPSS 0.004
CVE-2024-29808
WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id
Published 2024-03-26 · Analyzed
5.4EPSS 0.004
CVE-2024-29809
WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url
Published 2024-03-26 · Analyzed
5.4EPSS 0.004
CVE-2022-4058
Photo Gallery < 1.8.3 - Stored XSS via CSRF
Published 2022-12-19 · Modified
5.4EPSS 0.002
CVE-2024-33586
WordPress Photo Gallery by 10Web plugin <= 1.8.20 - Broken Access Control vulnerability
Published 2024-04-29 · Modified
5.3EPSS 0.004
CVE-2019-14798
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
Published 2019-08-09 · Modified
4.9EPSS 0.044
CVE-2021-24363
Photo Gallery < 1.5.75 - File Upload Path Traversal
Published 2021-08-16 · Modified
4.9EPSS 0.019
CVE-2023-1427
Photo Gallery by 10Web < 1.8.15 - Admin+ Path Traversal
Published 2023-04-17 · Modified
4.9EPSS 0.008
CVE-2020-9335
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.
Published 2020-02-25 · Modified
4.8EPSS 0.014
CVE-2021-24310
Photo Gallery < 1.5.67 - Authenticated Stored Cross-Site Scripting via Gallery Title
Published 2021-06-01 · Modified
4.8EPSS 0.011
CVE-2022-1394
Photo Gallery < 1.6.4 - Admin+ Stored Cross-Site Scripting
Published 2022-06-06 · Modified
4.8EPSS 0.010
CVE-2023-6924
Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget
Published 2024-01-11 · Modified
4.8EPSS 0.005
1 / 2Next →