Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total30
Critical4
High1
Medium24
Reset
Showing 21-30 of 30 records
Threat Entry Updated 2024-11-21

CVE-2022-1281 - Photo Gallery Plugin

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

PLUGIN Photo Gallery

CVE-2022-1281

CRITICAL CVSS 9.8 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-1282 - Photo Gallery Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the users when executing the editimage_bwg AJAX action.

PLUGIN Photo Gallery

CVE-2022-1282

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0169 - Photo Gallery Plugin

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

PLUGIN Photo Gallery

CVE-2022-0169

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-25041 - Photo Gallery Plugin

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

PLUGIN Photo Gallery

CVE-2021-25041

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24363 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector

PLUGIN Photo Gallery

CVE-2021-24363

MEDIUM CVSS 4.9 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24362 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue

PLUGIN Photo Gallery

CVE-2021-24362

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24462 - Photo Gallery Plugin

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Photo Gallery

CVE-2021-24462

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24310 - Photo Gallery Plugin

The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117

PLUGIN Photo Gallery

CVE-2021-24310

MEDIUM CVSS 4.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24291 - Photo Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)

PLUGIN Photo Gallery

CVE-2021-24291

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24139 - Photo Gallery Plugin

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

PLUGIN Photo Gallery

CVE-2021-24139

CRITICAL CVSS 9.8 2021-03-18
Scroll to top