Extension WordPress

Vulnérabilités Photo Gallery by 10Web – Mobile-Friendly Image Gallery, page 3

Cette page rassemble les failles publiées pour Photo Gallery by 10Web – Mobile-Friendly Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.

65Vulnérabilités
6Critiques
65Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Photo Gallery by 10Web – Mobile-Friendly Image Gallery

65 fiches

CVE-2021-24310 Moyenne · 4,8
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery <= 1.5.66 – Authenticated Stored Cross-Site Scripting via Gallery Title

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another…

Versions affectées

[*, 1.5.67)

Correctif

1.5.67

Publication

12/05/2021

CVE-2021-31693 Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.5.68 – Reflected Cross-Site Scripting <= 1.5.68 – Reflected Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'album_gallery_id_0', 'bwg_album_search_0', and 'type_0' parameters in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.5.68

Correctif

1.5.69

Publication

19/04/2021

CVE-2021-46889 Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.5.68 – Reflected Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'theme_id' parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.5.68

Correctif

1.5.69

Publication

19/04/2021

CVE-2021-24291 Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery <= 1.5.68 – Multiple Reflected Cross-Site Scripting

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to…

Versions affectées

[*, 1.5.69)

Correctif

1.5.69

Publication

19/04/2021

Vulnérabilité Moyenne · 6,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.5.68 – Cross-Site Scripting

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ bwg_search_X’ parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.5.68

Correctif

1.5.69

Publication

23/02/2021

CVE-2020-9335 Moyenne · 5,5
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.5.45 – Multiple Cross-Site Scripting Issues

Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.

Versions affectées

*-1.5.45

Correctif

1.5.46

Publication

25/02/2020

CVE-2017-12977 Élevée · 7,2
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.3.50 – Authenticated SQL Injection via tag_id Parameter

The Web-Dorado "Photo Gallery by WD – Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.

Versions affectées

[*, 1.3.51)

Correctif

1.3.51

Publication

20/08/2017

Vulnérabilité Moyenne · 4,1
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web < 1.3.43 – Authenticated Path Traversal

The Photo Gallery by 10Web plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.3.42. This allows administrative-level attackers to read the contents of arbitrary files on the server, which can contain sensitive…

Versions affectées

[*, 1.3.43)

Correctif

1.3.43

Publication

16/06/2017

Vulnérabilité Élevée · 8,8
Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web <= 1.3.37 – Authenticated SQL Injection

The Photo Gallery by 10Web plugin for WordPress is vulnerable to SQL Injection via the ‘album_id’ parameter in versions up to, and including, 1.3.37 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

[*, 1.3.38)

Correctif

1.3.38

Publication

02/05/2017

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités