目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Photo Gallery by 10Web – Mobile-Friendly Image Gallery 产品漏洞列表 / CVE 中文分析 19

Photo Gallery by 10Web – Mobile-Friendly Image Gallery 产品相关 19 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。

Photo Gallery by 10Web – Mobile-Friendly Image Gallery 是一款由 10Web 开发的 WordPress 图片展示插件,此处聚合了其相关的安全漏洞信息。本页收录了该产品的多种类型缺陷,涵盖从早期版本发布至今的历史漏洞记录,旨在提供全面的安全视角。读者可通过本页面追踪 10Web 官方针对此插件的安全公告,深入理解特定组件的常见弱点,并快速检索该产品的历史漏洞详情,以评估潜在风险并及时采取修复措施,保障网站安全。

ベンダー: Photo Gallery Team

CVE IDタイトルCVSS深刻度公開日
CVE-2026-9829 Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter CWE-89 6.5 Medium2026-06-06
CVE-2026-7048 Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute CWE-89 6.5 Medium2026-05-28
CVE-2026-1036 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion CWE-862 5.3 Medium2026-01-21
CVE-2025-2269 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter CWE-79 6.1 Medium2025-04-11
CVE-2024-9878 Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium2024-11-05
CVE-2024-5481 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function CWE-35 6.8 Medium2024-06-07
CVE-2024-5426 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG CWE-79 6.4 Medium2024-06-07
CVE-2024-2296 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG CWE-79 5.5 Medium2024-04-06
CVE-2024-0221 Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename CWE-22 9.1 Critical2024-02-05
CVE-2023-6924 Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget CWE-79 4.4 Medium2024-01-11
CVE-2022-1394 Photo Gallery < 1.6.4 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 -2022-06-06
CVE-2022-1282 Photo Gallery < 1.6.3 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-05-02
CVE-2022-1281 Photo Gallery < 1.6.3 - Unauthenticated SQL Injection CWE-89 9.8 -2022-05-02
CVE-2022-0169 Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection CWE-89 9.8 -2022-03-14
CVE-2021-25041 Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS) CWE-79 6.1 -2021-12-06
CVE-2021-24363 Photo Gallery < 1.5.75 - File Upload Path Traversal CWE-22 4.9 -2021-08-16
CVE-2021-24362 Photo Gallery < 1.5.75 - Stored Cross-Site Scripting via Uploaded SVG CWE-79 6.1 -2021-08-16
CVE-2021-24310 Photo Gallery < 1.5.67 - Authenticated Stored Cross-Site Scripting via Gallery Title CWE-79 4.8 -2021-06-01
CVE-2021-24291 Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS) CWE-79 6.1 -2021-05-14

Photo Gallery by 10Web – Mobile-Friendly Image Gallery 产品累计公开 19 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。