Vulnerabilities > 10Web > Low

DATE CVE VULNERABILITY TITLE RISK
2023-05-30 CVE-2023-2117 Unspecified vulnerability in 10Web Image Optimizer
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.
network
low complexity
10web
2.7
2022-06-08 CVE-2022-1394 Cross-site Scripting vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
network
10web CWE-79
3.5
2022-05-30 CVE-2022-1564 Cross-site Scripting vulnerability in 10Web Form Maker
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
network
10web CWE-79
3.5
2022-05-23 CVE-2022-1320 Cross-site Scripting vulnerability in 10Web Sliderby10Web
The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
network
10web CWE-79
3.5
2021-06-01 CVE-2021-24310 Cross-site Scripting vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard.
network
10web CWE-79
3.5
2020-02-25 CVE-2020-9335 Cross-site Scripting vulnerability in 10Web Photo Gallery
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress.
network
10web CWE-79
3.5
2020-02-08 CVE-2015-1394 Cross-site Scripting vulnerability in 10Web Photo Gallery
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.
network
10web CWE-79
3.5
2019-08-09 CVE-2019-14797 Cross-site Scripting vulnerability in 10Web Photo Gallery
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
network
10web CWE-79
3.5
2018-02-19 CVE-2015-2324 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
network
10web CWE-79
3.5