Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Photo Gallery by 10Web
10Web
Developer
1.8.35
Latest version
200,000
Installations
Mar 29, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
36 fixed
14 Mitigation rules
Admin+ Stored XSS vulnerability
< 1.8.29
May 19, 2025
WordPress Photo Gallery by 10Web plugin <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter vulnerability
<= 1.8.34
Apr 11, 2025
Unauthenticated Stored XSS vulnerability
< 1.8.34
Mar 31, 2025
Admin+ Stored XSS vulnerability
< 1.8.33
Mar 24, 2025
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 1.8.30
Nov 4, 2024
Admin+ Stored XSS vulnerability
<= 1.8.27
Oct 9, 2024
Cross Site Scripting (XSS) vulnerability
<= 1.8.27
Sep 23, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG vulnerability
<= 1.8.23
Jun 7, 2024
Authenticated (Contributor+) Path Traversal via esc_dir Function vulnerability
<= 1.8.23
Jun 7, 2024
Broken Access Control vulnerability
<= 1.8.25
May 27, 2024
Broken Access Control vulnerability
<= 1.8.20
Apr 25, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.8.21
Apr 16, 2024
Authenticated (Admin+) Stored Cross-Site Scripting via SVG vulnerability
<= 1.8.21
Apr 8, 2024
WordPress Photo Gallery by 10Web - Mobile-Friendly Image Gallery plugin <= 1.8.19 - Directory Traversal to Arbitrary File Rename vulnerability
<= 1.8.19
Jan 22, 2024
Authenticated Stored Cross-Site Scripting via Widget vulnerability
<= 1.8.18
Dec 21, 2023
Broken Access Control vulnerability
<= 1.8.15
Jun 19, 2023
Admin+ Path Traversal vulnerability
< 1.8.15
Apr 18, 2023
Stored XSS via CSRF vulnerability
< 1.8.3
Apr 18, 2023
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.7.0
Aug 10, 2022
Stored Cross-Site Scripting (XSS) vulnerability
<= 1.6.3
May 16, 2022
Unauthenticated SQL Injection (SQLi) vulnerability
<= 1.6.2
Apr 11, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.6.2
Apr 11, 2022
Multiple Reflected Cross-Site Scripting (XSS) vulnerabilities
<= 1.5.73
May 19, 2021
Cross-Site Scripting (XSS) vulnerability
<= 1.5.68
Feb 18, 2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.5.67
Feb 4, 2021
Unauthenticated SQL Injection (SQLi) vulnerability
<= 1.5.54
May 15, 2020
Multiple Cross-Site Scripting (XSS) vulnerabilities
<= 1.5.45
Feb 25, 2020
SQL Injection (SQLi) vulnerability
<= 1.5.34
Sep 9, 2019
Cross-Site Scripting (XSS) vulnerability
<= 1.5.34
Sep 9, 2019
SQL Injection (SQLi) vulnerability
<= 1.5.30
Jul 26, 2019
Cross-Site Scripting (XSS) vulnerability
<= 1.3.66
Feb 26, 2018
SQL Injection vulnerability
1.3.29
May 5, 2017
SQL Injection
<= 1.2.100
Jan 27, 2015
SQL Injection
<= 1.2.7
Jan 16, 2015
Multiple XSS
<= 1.1.30
Sep 11, 2014
Cross Site Request Forgery
<= 1.2.41
May 7, 2014