CVE-2024-10704
- EPSS 0.36%
- Veröffentlicht 29.11.2024 06:15:06
- Zuletzt bearbeitet 07.05.2025 00:07:12
The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability...
CVE-2024-9878
- EPSS 0.42%
- Veröffentlicht 05.11.2024 10:21:16
- Zuletzt bearbeitet 08.11.2024 15:25:45
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. T...
CVE-2024-5968
- EPSS 0.34%
- Veröffentlicht 09.10.2024 06:15:13
- Zuletzt bearbeitet 06.05.2025 18:21:40
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltere...
CVE-2024-44043
- EPSS 0.29%
- Veröffentlicht 06.10.2024 12:15:04
- Zuletzt bearbeitet 23.04.2026 15:19:03
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.27.
CVE-2024-35628
- EPSS 0.35%
- Veröffentlicht 11.06.2024 15:16:07
- Zuletzt bearbeitet 21.11.2024 09:20:31
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
CVE-2024-5481
- EPSS 0.73%
- Veröffentlicht 07.06.2024 10:15:11
- Zuletzt bearbeitet 08.04.2026 18:22:04
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste...
CVE-2024-5426
- EPSS 0.31%
- Veröffentlicht 07.06.2024 10:15:11
- Zuletzt bearbeitet 08.04.2026 17:19:03
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escapi...
CVE-2024-33586
- EPSS 0.37%
- Veröffentlicht 29.04.2024 13:15:30
- Zuletzt bearbeitet 28.04.2026 19:25:08
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.
CVE-2024-32583
- EPSS 0.35%
- Veröffentlicht 18.04.2024 10:15:13
- Zuletzt bearbeitet 28.04.2026 19:24:49
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Reflected XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.21.
CVE-2024-2296
- EPSS 0.44%
- Veröffentlicht 06.04.2024 09:15:07
- Zuletzt bearbeitet 08.04.2026 18:21:02
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping....