Vulnerabilities > 10Web > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-24310 Unspecified vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard.
network
low complexity
10web
4.8
2021-05-14 CVE-2021-24291 Unspecified vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)
network
low complexity
10web
6.1
2020-02-25 CVE-2020-9335 Cross-site Scripting vulnerability in 10Web Photo Gallery
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress.
network
low complexity
10web CWE-79
4.8
2020-02-08 CVE-2015-1394 Cross-site Scripting vulnerability in 10Web Photo Gallery
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.
network
low complexity
10web CWE-79
5.4
2019-09-08 CVE-2019-16118 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
network
low complexity
10web CWE-79
6.1
2019-09-08 CVE-2019-16117 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
network
low complexity
10web CWE-79
6.1
2019-08-09 CVE-2019-14798 Path Traversal vulnerability in 10Web Photo Gallery
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
network
low complexity
10web CWE-22
4.9
2019-08-09 CVE-2019-14797 Cross-site Scripting vulnerability in 10Web Photo Gallery
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
network
low complexity
10web CWE-79
5.4
2018-02-19 CVE-2015-2324 Cross-site Scripting vulnerability in 10Web Photo Gallery
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
10web CWE-79
5.4