Extension WordPress
Vulnérabilités Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Cette page rassemble les failles publiées pour Photo Gallery by 10Web – Mobile-Friendly Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Photo Gallery by 10Web – Mobile-Friendly Image Gallery
65 fiches
Photo Gallery by 10Web <= 1.8.41 – Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied…
*-1.8.41
1.8.42
05/06/2026
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 – Authenticated (Contributor+) SQL Injection
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-1.8.41
1.8.42
04/06/2026
Photo Gallery by 10Web <= 1.8.40 – Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user…
*-1.8.40
1.8.41
27/05/2026
Photo Gallery by 10Web <= 1.8.37 – Cross-Site Request Forgery
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.37. This is due to missing or incorrect nonce validation on a function. This makes it possible for…
*-1.8.37
1.8.38
08/02/2026
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 – Missing Authorization to Unauthenticated Arbitrary Comment Deletion
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This…
*-1.8.36
1.8.37
21/01/2026
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.38 – Authenticated (Editor+) Stored Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.38 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.8.38
1.8.39
25/12/2025
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘image_id’ parameter in all versions up to, and including, 1.8.34 due to insufficient input sanitization and output escaping.…
*-1.8.34
1.8.35
11/04/2025
Photo Gallery by 10Web <= 1.8.33 – Unauthenticated Stored Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.8.33 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.8.33
1.8.34
10/03/2025
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.32 – Authenticated (Admin+) Stored Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Titles in all versions up to, and including, 1.8.32 due to insufficient input sanitization and output escaping. This…
*-1.8.32
1.8.33
02/03/2025
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.30 – Authenticated (Admin+) Stored Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Titles in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This…
*-1.8.30
1.8.31
14/11/2024
Photo Gallery by 10Web <= 1.8.30 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This…
*-1.8.30
1.8.31
04/11/2024
Photo Gallery by 10Web <= 1.8.28 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This…
*-1.8.28
1.8.29
03/10/2024
Photo Gallery by 10Web <= 1.8.27 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-1.8.27
1.8.28
23/09/2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 – Authenticated (Contributor+) Path Traversal via esc_dir Function
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut…
*-1.8.23
1.8.24
06/06/2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 – Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter in all versions up to, and including, 1.8.23 due to insufficient input sanitization and output escaping.…
*-1.8.23
1.8.24
06/06/2024
Photo Gallery by 10Web <= 1.8.25 – Missing Authorization to Notice Dismissal
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the dismiss_notice function in all versions up to, and including, 1.8.25. This makes it…
*-1.8.25
1.8.26
27/05/2024
Photo Gallery by 10Web <= 1.8.20 – Missing Authorization
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.20. This makes it possible…
*-1.8.20
1.8.21
25/04/2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 – Authenticated (Admin+) Stored Cross-Site Scripting via SVG
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping.…
*-1.8.21
1.8.22
05/04/2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 – Reflected Cross-Site Scripting via 'image_url'
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping.…
*-1.8.21
1.8.22
26/03/2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 – Reflected Cross-Site Scripting via 'thumb_url'
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping.…
*-1.8.21
1.8.22
26/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.