CVE-2021-24139
- EPSS 5.42%
- Veröffentlicht 18.03.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:52:26
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
CVE-2020-9335
- EPSS 1.36%
- Veröffentlicht 25.02.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:40:25
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other user...
CVE-2015-1394
- EPSS 2.33%
- Veröffentlicht 08.02.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 02:25:20
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clip...
CVE-2019-16119
- EPSS 25.44%
- Veröffentlicht 08.09.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:05
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
CVE-2019-16118
- EPSS 5.3%
- Veröffentlicht 08.09.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:05
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
CVE-2019-16117
- EPSS 4.61%
- Veröffentlicht 08.09.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:04
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
CVE-2015-9380
- EPSS 0.82%
- Veröffentlicht 30.08.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 02:40:29
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
CVE-2019-14798
- EPSS 4.43%
- Veröffentlicht 09.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:22
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
CVE-2019-14797
- EPSS 1.3%
- Veröffentlicht 09.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:22
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
- EPSS 4.48%
- Veröffentlicht 30.07.2019 18:15:16
- Zuletzt bearbeitet 21.11.2024 04:26:28
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/m...