Vulnerabilities > 10Web > Photo Gallery > 1.2.40
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-03-26 | CVE-2024-29809 | Unspecified vulnerability in 10Web Photo Gallery The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. | 5.4 |
2024-03-26 | CVE-2024-29810 | Unspecified vulnerability in 10Web Photo Gallery The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. | 5.4 |
2024-03-26 | CVE-2024-29832 | Unspecified vulnerability in 10Web Photo Gallery The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. | 6.1 |
2024-03-26 | CVE-2024-29833 | Unspecified vulnerability in 10Web Photo Gallery The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. | 5.4 |
2024-02-05 | CVE-2024-0221 | Path Traversal vulnerability in 10Web Photo Gallery The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. | 7.2 |
2024-01-11 | CVE-2023-6924 | Cross-site Scripting vulnerability in 10Web Photo Gallery The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. | 4.8 |
2023-06-07 | CVE-2021-46889 | Cross-site Scripting vulnerability in 10Web Photo Gallery The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. | 6.1 |
2023-04-17 | CVE-2023-1427 | Unspecified vulnerability in 10Web Photo Gallery - The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector. | 4.9 |
2022-12-19 | CVE-2022-4058 | Unspecified vulnerability in 10Web Photo Gallery The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later on in another page, which could lead to Stored XSS issue when an attacker makes a logged in admin open a malicious URL or page under their control. | 5.4 |
2022-06-08 | CVE-2022-1394 | Unspecified vulnerability in 10Web Photo Gallery The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed | 4.8 |