CVE-2026-92974
- EPSS 0.23%
- Veröffentlicht 03.10.2026 06:38:21
- Zuletzt bearbeitet 06.10.2026 15:04:52
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and outp...
CVE-2026-102377
- EPSS 0.29%
- Veröffentlicht 30.09.2026 17:39:06
- Zuletzt bearbeitet 30.09.2026 19:04:41
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-85652
- EPSS 0.41%
- Veröffentlicht 18.09.2026 07:40:04
- Zuletzt bearbeitet 18.09.2026 20:17:29
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the user supplie...
CVE-2026-86311
- EPSS 0.2%
- Veröffentlicht 17.09.2026 03:39:14
- Zuletzt bearbeitet 17.09.2026 21:12:30
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output e...
CVE-2026-12865
- EPSS 0.2%
- Veröffentlicht 02.09.2026 06:00:16
- Zuletzt bearbeitet 03.09.2026 17:49:19
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthen...
CVE-2026-9829
- EPSS 0.47%
- Veröffentlicht 06.06.2026 04:28:20
- Zuletzt bearbeitet 23.07.2026 07:10:00
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41 due to insufficient escaping on th...
CVE-2026-7048
- EPSS 0.5%
- Veröffentlicht 28.05.2026 07:43:42
- Zuletzt bearbeitet 28.05.2026 13:45:25
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplie...
CVE-2026-32330
- EPSS 0.11%
- Veröffentlicht 13.03.2026 11:41:55
- Zuletzt bearbeitet 22.04.2026 21:30:26
Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request Forgery.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37.
CVE-2026-27360
- EPSS 0.2%
- Veröffentlicht 19.02.2026 20:35:42
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.38.
CVE-2026-1036
- EPSS 0.22%
- Veröffentlicht 21.01.2026 23:23:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This m...