Extension WordPress
Vulnérabilités Photo Gallery by 10Web – Mobile-Friendly Image Gallery, page 3
Cette page rassemble les failles publiées pour Photo Gallery by 10Web – Mobile-Friendly Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Photo Gallery by 10Web – Mobile-Friendly Image Gallery
65 fiches
Photo Gallery <= 1.5.66 – Authenticated Stored Cross-Site Scripting via Gallery Title
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another…
[*, 1.5.67)
1.5.67
12/05/2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.5.68 – Reflected Cross-Site Scripting <= 1.5.68 – Reflected Cross-Site Scripting
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'album_gallery_id_0', 'bwg_album_search_0', and 'type_0' parameters in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes…
*-1.5.68
1.5.69
19/04/2021
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.5.68 – Reflected Cross-Site Scripting
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'theme_id' parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.5.68
1.5.69
19/04/2021
Photo Gallery <= 1.5.68 – Multiple Reflected Cross-Site Scripting
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to…
[*, 1.5.69)
1.5.69
19/04/2021
Photo Gallery by 10Web <= 1.5.68 – Cross-Site Scripting
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ bwg_search_X’ parameter in versions up to, and including, 1.5.68 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.5.68
1.5.69
23/02/2021
Photo Gallery <= 1.5.67 – Reflected Cross-Site Scripting
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action
[*, 1.5.68)
1.5.68
03/02/2021
Photo Gallery by 10Web <= 1.5.54 – SQL Injection via bwg_search_x Parameter
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
[*, 1.5.55)
1.5.55
15/05/2020
Photo Gallery by 10Web <= 1.5.45 – Multiple Cross-Site Scripting Issues
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.
*-1.5.45
1.5.46
25/02/2020
Photo Gallery by 10Web <= 1.5.34 – Cross-Site Scripting
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
[*, 1.5.35)
1.5.35
08/09/2019
Photo Gallery by 10Web <= 1.5.34 – SQL Injection
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
[*, 1.5.35)
1.5.35
08/09/2019
Photo Gallery by 10Web <= 1.5.34 – Cross-Site Scripting
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
*-1.5.34
1.5.35
08/09/2019
Photo Gallery by 10Web <= 1.5.30 – SQL Injection
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
[*, 1.5.31)
1.5.31
26/07/2019
Photo Gallery by 10Web <= 1.5.24 – Authenticated Local File Inclusion
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
*-1.5.24
1.5.25
15/05/2019
Photo Gallery by 10Web <= 1.5.22 – Authenticated Cross-Site Scripting
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
*-1.5.22
1.5.23
13/05/2019
Photo Gallery by 10Web <= 1.3.66 – Cross-Site Scripting
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.66 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web…
[*, 1.3.67)
1.3.67
14/12/2017
Photo Gallery by 10Web <= 1.3.50 – Authenticated SQL Injection via tag_id Parameter
The Web-Dorado "Photo Gallery by WD – Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
[*, 1.3.51)
1.3.51
20/08/2017
Photo Gallery by 10Web < 1.3.43 – Authenticated Path Traversal
The Photo Gallery by 10Web plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.3.42. This allows administrative-level attackers to read the contents of arbitrary files on the server, which can contain sensitive…
[*, 1.3.43)
1.3.43
16/06/2017
Photo Gallery by 10Web <= 1.3.37 – Authenticated SQL Injection
The Photo Gallery by 10Web plugin for WordPress is vulnerable to SQL Injection via the ‘album_id’ parameter in versions up to, and including, 1.3.37 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 1.3.38)
1.3.38
02/05/2017
Photo Gallery by 10Web <= 1.2.12 – Authenticated Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
[*, 1.2.13)
1.2.13
13/03/2015
Photo Gallery by 10Web <= 1.2.5 – Unrestricted File Upload
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
[*, 1.2.6)
1.2.6
12/02/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.