Vulnerabilities > 10Web > Photo Gallery > Low

DATE CVE VULNERABILITY TITLE RISK
2022-06-08 CVE-2022-1394 Cross-site Scripting vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
network
10web CWE-79
3.5
2021-06-01 CVE-2021-24310 Cross-site Scripting vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard.
network
10web CWE-79
3.5
2020-02-25 CVE-2020-9335 Cross-site Scripting vulnerability in 10Web Photo Gallery
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress.
network
10web CWE-79
3.5
2020-02-08 CVE-2015-1394 Cross-site Scripting vulnerability in 10Web Photo Gallery
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.
network
10web CWE-79
3.5
2019-08-09 CVE-2019-14797 Cross-site Scripting vulnerability in 10Web Photo Gallery
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
network
10web CWE-79
3.5
2018-02-19 CVE-2015-2324 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
network
10web CWE-79
3.5