10Web Photo Gallery vulnerabilities
49 known vulnerabilities affecting 10web/photo_gallery.
Total CVEs
49
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH6MEDIUM37LOW1
Vulnerabilities
Page 1 of 3
CVE-2024-8670MEDIUMCVSS 4.8fixed in 1.8.292025-05-15
CVE-2024-8670 [MEDIUM] CWE-79 CVE-2024-8670: The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its
The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2025-0613MEDIUMCVSS 6.1fixed in 1.8.342025-03-31
CVE-2025-0613 [MEDIUM] CWE-79 CVE-2025-0613: The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment ad
The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed
nvd
CVE-2024-13124LOWCVSS 3.5fixed in 1.8.332025-03-24
CVE-2024-13124 [LOW] CWE-79 CVE-2024-13124: The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its
The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2023-33995MEDIUMCVSS 4.3fixed in 1.8.162024-12-13
CVE-2023-33995 [MEDIUM] CWE-862 CVE-2023-33995: Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting I
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through 1.8.15.
nvd
CVE-2024-10704MEDIUMCVSS 4.8fixed in 1.8.312024-11-29
CVE-2024-10704 [MEDIUM] CWE-79 CVE-2024-10704: The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its
The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2024-9878MEDIUMCVSS 4.8fixed in 1.8.312024-11-05
CVE-2024-9878 [MEDIUM] CWE-79 CVE-2024-9878: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Sto
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in
nvd
CVE-2024-5968MEDIUMCVSS 4.8fixed in 1.8.282024-10-09
CVE-2024-5968 [MEDIUM] CWE-79 CVE-2024-5968: The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape som
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2024-44043MEDIUMCVSS 4.8fixed in 1.8.282024-10-06
CVE-2024-44043 [MEDIUM] CWE-79 CVE-2024-44043: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.27.
nvd
CVE-2024-35628MEDIUMCVSS 4.3fixed in 1.8.262024-06-11
CVE-2024-35628 [MEDIUM] CWE-862 CVE-2024-35628: Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
nvd
CVE-2024-5481HIGHCVSS 8.8fixed in 1.8.242024-06-07
CVE-2024-5481 [MEDIUM] CWE-35 CVE-2024-5481: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Pat
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste (copy) the contents of arbitrary files on the server, which can contain sensitive information, and to c
nvd
CVE-2024-5426MEDIUMCVSS 5.4fixed in 1.8.242024-06-07
CVE-2024-5426 [MEDIUM] CWE-79 CVE-2024-5426: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Sto
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that wil
nvd
CVE-2024-33586MEDIUMCVSS 5.3fixed in 1.8.212024-04-29
CVE-2024-33586 [MEDIUM] CWE-862 CVE-2024-33586: Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.
nvd
CVE-2024-32583MEDIUMCVSS 6.1fixed in 1.8.222024-04-18
CVE-2024-32583 [HIGH] CWE-79 CVE-2024-32583: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Reflected XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.21.
nvd
CVE-2024-2296MEDIUMCVSS 4.8fixed in 1.8.222024-04-06
CVE-2024-2296 [MEDIUM] CWE-79 CVE-2024-2296: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Sto
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrar
nvd
CVE-2024-29809MEDIUMCVSS 5.4fixed in 1.8.222024-03-26
CVE-2024-29809 [MEDIUM] CWE-79 CVE-2024-29809: The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable
The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with perm
nvd
CVE-2024-29833MEDIUMCVSS 5.4fixed in 1.8.222024-03-26
CVE-2024-29833 [MEDIUM] CWE-79 CVE-2024-29833: The image upload component allows SVG files and the regular expression used to remove script tags ca
The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An attacker must target an authenticated user with permissions to access this f
nvd
CVE-2024-29808MEDIUMCVSS 5.4fixed in 1.8.222024-03-26
CVE-2024-29808 [MEDIUM] CWE-79 CVE-2024-29808: The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable
The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_id parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permiss
nvd
CVE-2024-29832MEDIUMCVSS 6.1fixed in 1.8.222024-03-26
CVE-2024-29832 [MEDIUM] CWE-79 CVE-2024-29832: The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable
The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the current_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. No authentication is required to exploit this issue.
Note
nvd
CVE-2024-29810MEDIUMCVSS 5.4fixed in 1.8.222024-03-26
CVE-2024-29810 [MEDIUM] CWE-79 CVE-2024-29810: The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable
The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with perm
nvd
CVE-2024-0221HIGHCVSS 7.2fixed in 1.8.202024-02-05
CVE-2024-0221 [CRITICAL] CWE-22 CVE-2024-0221: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Dir
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This makes it possible for authenticated attackers to rename arbitrary files on the server. This can lead to site takeovers if the wp-config.php file of a site
nvd
1 / 3Next →