📦 Photo Gallery

by 10web

🔍 What is Photo Gallery?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-1281

CRITICAL CVSS 9.8 May 2, 2022

This CVE describes an SQL injection vulnerability in the Photo Gallery WordPress plugin. Attackers can exploit this by sending malicious input through the filter_tag parameter, potentially allowing th...

CVE-2022-0169

CRITICAL CVSS 9.8 Mar 14, 2022

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on WordPress sites using the Photo Gallery by 10Web plugin. Attackers can potentially steal sensitive data, modify...

CVE-2021-24139

CRITICAL CVSS 9.8 Mar 18, 2021

This vulnerability allows attackers to execute arbitrary SQL commands on WordPress sites using the Photo Gallery plugin. It affects all WordPress installations with the 10Web Photo Gallery plugin vers...

CVE-2025-0613

MEDIUM CVSS 6.1 Mar 31, 2025

The Photo Gallery by 10Web WordPress plugin before version 1.8.34 contains a stored cross-site scripting (XSS) vulnerability. Unauthenticated attackers can inject malicious scripts into image comments...

CVE-2024-9878

MEDIUM CVSS 4.4 Nov 5, 2024

This vulnerability allows authenticated attackers with administrator-level permissions to inject malicious scripts into WordPress admin settings pages. The injected scripts execute whenever users acce...

CVE-2024-35628

MEDIUM CVSS 4.3 Jun 11, 2024

This CVE describes a Missing Authorization vulnerability in the Photo Gallery by 10Web WordPress plugin. It allows unauthorized users to perform actions that should require authentication, affecting a...

CVE-2024-5481

MEDIUM CVSS 6.8 Jun 7, 2024

The Photo Gallery by 10Web WordPress plugin has a path traversal vulnerability in the esc_dir function that allows authenticated attackers to copy arbitrary files (potentially containing sensitive inf...