Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Minimum safe version
1.8.39
Update to 1.8.39 or later to address 82 fixable vulnerabilities
CVE-2026-32330
CVE-2026-27360
Photo Gallery by 10Web <= 1.8.33 - Unauthenticated Stored Cross-Site Scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter
CVE-2024-13124
CVE-2024-10704
CVE-2024-9878
Photo Gallery by 10Web <= 1.8.28 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2024-5968
CVE-2024-44043
CVE-2024-5481
CVE-2024-5426
CVE-2024-35628
CVE-2024-33586
CVE-2024-32583
CVE-2024-2296
CVE-2024-29833
CVE-2024-29832
CVE-2024-29810
CVE-2024-29809
CVE-2024-29808
CVE-2024-0221
WordPress Photo Gallery by 10Web Plugin <= 1.8.18 is vulnerable to Cross Site Scripting (XSS)
Photo Gallery by WD <= 1.3.35 - Authenticated SQL Injection
Photo Gallery by WD <= 1.3.42 - Authenticated Path Traversal
Photo Gallery by WD <= 1.3.66 - Cross-Site Scripting (XSS)
Photo Gallery by 10web < 1.5.69 - Reflected Cross-Site Scripting (XSS)
Photo Gallery < 1.5.79 - Stored XSS via Uploaded SVG in Zip
Photo Gallery < 1.7.1 - Reflected Cross-Site Scripting
CVE-2023-33995
CVE-2021-31693
CVE-2021-46889
Photo Gallery <= 1.8.15 - Missing Authorization
Photo Gallery by 10Web <= 1.8.14 - Authenticated (Administrator+) Directory Traversal
CVE-2014-9312
Photo Gallery by 10Web <= 1.3.37 - Authenticated SQL Injection
Photo Gallery by 10Web < 1.3.43 - Authenticated Path Traversal
Photo Gallery by 10Web <= 1.3.66 - Cross-Site Scripting
Photo Gallery by 10Web <= 1.5.68 - Cross-Site Scripting
Photo Gallery by 10Web <= 1.5.78 - Stored Cross-Site Scripting via Uploaded SVG
Photo Gallery by 10Web <= 1.6.6 - Reflected Cross-Site Scripting
Photo Gallery by 10Web <= 1.6.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Photo Gallery by 10Web <= 1.6.8 - Authenticated (Admin+) Cross-Site Scripting
Photo Gallery <= 1.7.0 - Reflected Cross-Site Scripting
Photo Gallery by 10Web <= 1.8.0 - Reflected Cross-Site Scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.7 - Open Redirect
WordPress Photo Gallery by 10Web Plugin < 1.8.3 is vulnerable to Cross Site Scripting (XSS)
WordPress Photo Gallery plugin <= 1.7.0 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Photo Gallery Plugin <= 1.2.41 - Cross Site Request Forgery
WordPress Web-Dorado Gallery plugin 1.3.29 - SQL Injection vulnerability
CVE-2022-1394
WordPress Photo Gallery by WD plugin <=1.3.66 - Cross-Site Scripting (XSS) vulnerability
WordPress Photo Gallery by 10Web plugin <= 1.5.30 - SQL Injection (SQLi) vulnerability
WordPress Photo Gallery by 10Web plugin <= 1.5.34 - Cross-Site Scripting (XSS) vulnerability
WordPress Photo Gallery by 10Web plugin <= 1.5.54 - Unauthenticated SQL Injection (SQLi) vulnerability
WordPress Photo Gallery by 10Web plugin <= 1.5.67 - Cross-Site Scripting (XSS) vulnerability
WordPress Photo Gallery by 10Web plugin <= 1.5.68 - Cross-Site Scripting (XSS) vulnerability
WordPress Photo Gallery by 10Web plugin <= 1.5.73 - Multiple Reflected Cross-Site Scripting (XSS) vulnerabilities
CVE-2022-1282
CVE-2022-1281
CVE-2014-6315
CVE-2015-1055
CVE-2015-1393
CVE-2017-12977
CVE-2015-2324
CVE-2019-14313
CVE-2019-14798
CVE-2019-14797
CVE-2015-9380
WordPress Photo Gallery by 10Web plugin <= 1.5.34 - SQL Injection (SQLi) vulnerability
CVE-2019-16118
CVE-2019-16117
CVE-2015-1394
CVE-2020-9335
CVE-2021-24139
CVE-2021-24291
CVE-2021-24310
CVE-2021-24363
CVE-2021-24362
CVE-2021-25041
CVE-2022-0169