Vulnerabilities > 10Web > Photo Gallery

DATE CVE VULNERABILITY TITLE RISK
2019-09-08 CVE-2019-16119 SQL Injection vulnerability in 10Web Photo Gallery
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
network
low complexity
10web CWE-89
critical
9.8
2019-09-08 CVE-2019-16118 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
network
low complexity
10web CWE-79
6.1
2019-09-08 CVE-2019-16117 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
network
low complexity
10web CWE-79
6.1
2019-08-30 CVE-2015-9380 Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
network
low complexity
10web CWE-352
8.8
2019-08-09 CVE-2019-14798 Path Traversal vulnerability in 10Web Photo Gallery
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
network
low complexity
10web CWE-22
4.9
2019-08-09 CVE-2019-14797 Cross-site Scripting vulnerability in 10Web Photo Gallery
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
network
low complexity
10web CWE-79
5.4
2019-07-30 CVE-2019-14313 SQL Injection vulnerability in 10Web Photo Gallery
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.
network
low complexity
10web CWE-89
critical
9.8
2018-02-19 CVE-2015-2324 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
10web CWE-79
5.4
2017-08-28 CVE-2014-9312 Unrestricted Upload of File with Dangerous Type vulnerability in 10Web Photo Gallery 1.2.5
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
network
low complexity
10web CWE-434
8.8
2017-08-21 CVE-2017-12977 SQL Injection vulnerability in 10Web Photo Gallery
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php.
network
low complexity
10web CWE-89
7.2