Extension WordPress

Vulnérabilités Photo Gallery by 10Web – Mobile-Friendly Image Gallery, page 2

Cette page rassemble les failles publiées pour Photo Gallery by 10Web – Mobile-Friendly Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.

65Vulnérabilités
6Critiques
65Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Photo Gallery by 10Web – Mobile-Friendly Image Gallery

65 fiches

CVE-2024-29808 Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 – Reflected Cross-Site Scripting via 'image_id'

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'image_id' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.8.21

Correctif

1.8.22

Publication

26/03/2024

CVE-2024-29832 Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 – Reflected Cross-Site Scripting via 'current_url'

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_url' parameter in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.8.21

Correctif

1.8.22

Publication

26/03/2024

CVE-2024-0221 Critique · 9,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.19 – Directory Traversal to Arbitrary File Rename

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 via the rename_item function. This makes it possible for authenticated attackers to rename…

Versions affectées

*-1.8.19

Correctif

1.8.20

Publication

19/01/2024

CVE-2023-6924 Moyenne · 4,4
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.8.18 – Authenticated (Administrator+) Stored Cross-Site Scripting via Widget

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up to, and including, 1.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-1.8.18

Correctif

1.8.19

Publication

21/12/2023

CVE-2023-1427 Moyenne · 4,9
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.8.14 – Authenticated (Administrator+) Directory Traversal

The Photo Gallery plugin by 10Web for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.8.14 via the dir parameter. This allows authenticated attackers with administrator-level permissions to upload files to arbitrary directories on…

Versions affectées

*-1.8.14

Correctif

1.8.15

Publication

21/03/2023

CVE-2022-4058 Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery <= 1.8.2 – Cross-Site Request Forgery to Stored Cross-Site Scripting

The Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation one of its functions. This makes it possible for unauthenticated…

Versions affectées

*-1.8.2

Correctif

1.8.3

Publication

28/11/2022

Vulnérabilité Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.8.0 – Reflected Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘curr_url’ parameter in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.8.0

Correctif

1.8.1

Publication

03/11/2022

Vulnérabilité Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery <= 1.7.0 – Reflected Cross-Site Scripting

The Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.7.0

Correctif

1.7.1

Publication

10/08/2022

Vulnérabilité Moyenne · 5,5
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.6.8 – Authenticated (Admin+) Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers…

Versions affectées

*-1.6.8

Correctif

1.6.9

Publication

01/07/2022

Vulnérabilité Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.6.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-1.6.7

Correctif

1.6.8

Publication

28/06/2022

CVE-2022-1394 Moyenne · 5,5
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.6.3 – Authenticated (Admin+) Stored Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Watermark font size" and "Watermark opacity" fields in versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping.…

Versions affectées

[*, 1.6.4)

Correctif

1.6.4

Publication

16/05/2022

CVE-2022-0169 Critique · 9,8
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.5.87 – Unauthenticated SQL Injection via bwg_tag_id_bwg_thumbnails_0 Parameter

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an…

Versions affectées

[*, 1.6.0)

Correctif

1.6.0

Publication

15/02/2022

Vulnérabilité Moyenne · 6,4
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.5.78 – Stored Cross-Site Scripting via Uploaded SVG

The Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.78 due to insufficient sanitization and escaping on SVG uploads. This makes it possible for low-level authenticated attackers, such as…

Versions affectées

*-1.5.78

Correctif

1.5.79

Publication

19/07/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités