CVE-2024-5968
- EPSS 0.18%
- Veröffentlicht 09.10.2024 06:15:13
- Zuletzt bearbeitet 06.05.2025 18:21:40
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltere...
CVE-2024-44043
- EPSS 0.16%
- Veröffentlicht 06.10.2024 12:15:04
- Zuletzt bearbeitet 01.04.2026 16:17:57
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.27.
CVE-2024-35628
- EPSS 0.16%
- Veröffentlicht 11.06.2024 15:16:07
- Zuletzt bearbeitet 21.11.2024 09:20:31
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
CVE-2024-5481
- EPSS 1.6%
- Veröffentlicht 07.06.2024 10:15:11
- Zuletzt bearbeitet 08.04.2026 18:22:04
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste...
CVE-2024-5426
- EPSS 0.36%
- Veröffentlicht 07.06.2024 10:15:11
- Zuletzt bearbeitet 08.04.2026 17:19:03
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escapi...
CVE-2024-33586
- EPSS 0.16%
- Veröffentlicht 29.04.2024 13:15:30
- Zuletzt bearbeitet 06.03.2025 15:00:11
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.
CVE-2024-32583
- EPSS 0.15%
- Veröffentlicht 18.04.2024 10:15:13
- Zuletzt bearbeitet 06.03.2025 15:00:11
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Reflected XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.21.
CVE-2024-2296
- EPSS 0.16%
- Veröffentlicht 06.04.2024 09:15:07
- Zuletzt bearbeitet 08.04.2026 18:21:02
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping....
CVE-2024-29833
- EPSS 0.05%
- Veröffentlicht 26.03.2024 16:15:13
- Zuletzt bearbeitet 09.04.2025 15:42:02
The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace ...
CVE-2024-29832
- EPSS 0.13%
- Veröffentlicht 26.03.2024 16:15:12
- Zuletzt bearbeitet 09.04.2025 15:41:45
The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the current_url parameter is embedded within an existing JavaScript within the response allowing arbit...