Pricing
Case studies
Login
Start trial
Photo Gallery by 10Web
10Web
Developer
1.8.39
Latest version
200,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
40 patched
14 Mitigation rules
Cross Site Request Forgery (CSRF) vulnerability
<= 1.8.37
08/02/2026
Admin+ Stored XSS vulnerability
< 1.8.31
30/01/2026
Missing Authorization to Unauthenticated Arbitrary Comment Deletion vulnerability
<= 1.8.36
21/01/2026
Cross Site Scripting (XSS) vulnerability
<= 1.8.38
25/12/2025
Admin+ Stored XSS vulnerability
< 1.8.29
19/05/2025
WordPress Photo Gallery by 10Web plugin <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter vulnerability
<= 1.8.34
11/04/2025
Unauthenticated Stored XSS vulnerability
< 1.8.34
31/03/2025
Admin+ Stored XSS vulnerability
< 1.8.33
24/03/2025
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 1.8.30
04/11/2024
Admin+ Stored XSS vulnerability
<= 1.8.27
09/10/2024
Cross Site Scripting (XSS) vulnerability
<= 1.8.27
23/09/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG vulnerability
<= 1.8.23
07/06/2024
Authenticated (Contributor+) Path Traversal via esc_dir Function vulnerability
<= 1.8.23
07/06/2024
Broken Access Control vulnerability
<= 1.8.25
27/05/2024
Broken Access Control vulnerability
<= 1.8.20
25/04/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.8.21
16/04/2024
Authenticated (Admin+) Stored Cross-Site Scripting via SVG vulnerability
<= 1.8.21
08/04/2024
WordPress Photo Gallery by 10Web - Mobile-Friendly Image Gallery plugin <= 1.8.19 - Directory Traversal to Arbitrary File Rename vulnerability
<= 1.8.19
22/01/2024
Authenticated Stored Cross-Site Scripting via Widget vulnerability
<= 1.8.18
21/12/2023
Broken Access Control vulnerability
<= 1.8.15
19/06/2023
Admin+ Path Traversal vulnerability
< 1.8.15
18/04/2023
Stored XSS via CSRF vulnerability
< 1.8.3
18/04/2023
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.7.0
10/08/2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 1.6.3
16/05/2022
Unauthenticated SQL Injection (SQLi) vulnerability
<= 1.6.2
11/04/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.6.2
11/04/2022
Multiple Reflected Cross-Site Scripting (XSS) vulnerabilities
<= 1.5.73
19/05/2021
Cross-Site Scripting (XSS) vulnerability
<= 1.5.68
18/02/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.5.67
04/02/2021
Unauthenticated SQL Injection (SQLi) vulnerability
<= 1.5.54
15/05/2020
Multiple Cross-Site Scripting (XSS) vulnerabilities
<= 1.5.45
25/02/2020
SQL Injection (SQLi) vulnerability
<= 1.5.34
09/09/2019
Cross-Site Scripting (XSS) vulnerability
<= 1.5.34
09/09/2019
SQL Injection (SQLi) vulnerability
<= 1.5.30
26/07/2019
Cross-Site Scripting (XSS) vulnerability
<= 1.3.66
26/02/2018
SQL Injection vulnerability
1.3.29
05/05/2017
SQL Injection
<= 1.2.100
27/01/2015
SQL Injection
<= 1.2.7
16/01/2015
Multiple XSS
<= 1.1.30
11/09/2014
Cross Site Request Forgery
<= 1.2.41
07/05/2014