Photo Gallery by 10Web – Mobile-Friendly Image Gallery

38 known CVEs 100K+ active installs

Scan My Site Free

UNKNOWN: 38
Known Vulnerabilities 38
CVE-2026-9829 UNKNOWN EPSS 0.4%
Published 2026-06-06 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and in
CVE-2026-1036 UNKNOWN EPSS 0.1%
Published 2026-01-22 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in
CVE-2023-33995 UNKNOWN EPSS 0.4%
Published 2024-12-13 · Affected: *
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from
CVE-2023-33995 UNKNOWN EPSS 0.4%
Published 2024-12-13 · Affected: *
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from
CVE-2024-44043 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 1
CVE-2024-44043 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 1
CVE-2024-44043 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 1
CVE-2024-44043 UNKNOWN EPSS 0.2%
Published 2024-10-06 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 1
CVE-2024-5481 UNKNOWN EPSS 0.5%
Published 2024-06-07 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it pos
CVE-2024-5481 UNKNOWN EPSS 0.5%
Published 2024-06-07 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it pos
CVE-2024-5426 UNKNOWN EPSS 0.2%
Published 2024-06-07 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to
CVE-2024-5426 UNKNOWN EPSS 0.2%
Published 2024-06-07 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to
CVE-2024-2296 UNKNOWN EPSS 0.4%
Published 2024-04-06 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to in
CVE-2024-2296 UNKNOWN EPSS 0.4%
Published 2024-04-06 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to in
CVE-2024-29921 UNKNOWN EPSS 0.3%
Published 2024-03-27 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Sups
CVE-2024-29921 UNKNOWN EPSS 0.3%
Published 2024-03-27 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Sups
CVE-2024-29921 UNKNOWN EPSS 0.3%
Published 2024-03-27 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Sups
CVE-2024-29921 UNKNOWN EPSS 0.3%
Published 2024-03-27 · Affected: *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Sups
CVE-2024-0221 UNKNOWN EPSS 0.7%
Published 2024-02-05 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This mak
CVE-2024-0221 UNKNOWN EPSS 0.7%
Published 2024-02-05 · Affected: *
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This mak
CVE-2023-6924 UNKNOWN EPSS 0.4%
Published 2024-01-11 · Affected: *
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output esca
CVE-2023-6924 UNKNOWN EPSS 0.4%
Published 2024-01-11 · Affected: *
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output esca
CVE-2021-31693 UNKNOWN EPSS 0.3%
Published 2022-11-29 · Affected: *
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-2429
CVE-2021-31693 UNKNOWN EPSS 0.3%
Published 2022-11-29 · Affected: *
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-2429
CVE-2021-31693 UNKNOWN EPSS 0.3%
Published 2022-11-29 · Affected: *
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-2429
CVE-2021-31693 UNKNOWN EPSS 0.3%
Published 2022-11-29 · Affected: *
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-2429
CVE-2014-9312 UNKNOWN EPSS 1.0%
Published 2017-08-28 · Affected: <1.2.5
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
CVE-2017-12977 UNKNOWN EPSS 0.7%
Published 2017-08-21 · Affected: *
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in ad
CVE-2008-6790 UNKNOWN EPSS 0.8%
Published 2009-05-04 · Affected: <2.2
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.
CVE-2008-6790 UNKNOWN EPSS 0.8%
Published 2009-05-04 · Affected: <2.2
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.
CVE-2008-6789 UNKNOWN EPSS 0.6%
Published 2009-05-04 · Affected: <2.2
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a d
CVE-2008-6789 UNKNOWN EPSS 0.6%
Published 2009-05-04 · Affected: <2.2
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a d
CVE-2008-6788 UNKNOWN EPSS 0.6%
Published 2009-05-04 · Affected: <2.2
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to inde
CVE-2008-6788 UNKNOWN EPSS 0.6%
Published 2009-05-04 · Affected: <2.2
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to inde
CVE-2008-6348 UNKNOWN EPSS 0.6%
Published 2009-03-02 · Affected: <1.2
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id pa
CVE-2008-6348 UNKNOWN EPSS 0.6%
Published 2009-03-02 · Affected: <1.2
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id pa
CVE-2006-3688 UNKNOWN EPSS 0.7%
Published 2006-07-21 · Affected: <1.0
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-3688 UNKNOWN EPSS 0.7%
Published 2006-07-21 · Affected: <1.0
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Is Photo Gallery by 10Web &#8211; Mobile-Friendly Image Gallery running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free