Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Photo Gallery by 10Web – Mobile-Friendly Image Gallery, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities and weaknesses associated with the Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin, classified under common weakness types within the WordPress ecosystem. The content aggregates a comprehensive list of known issues, ranging from cross-site scripting and privilege escalation to improper access control flaws, covering all disclosed vulnerabilities from the plugin’s initial release through the most recent updates. Users can utilize this resource to track the vendor's security advisories over time, gain a deeper understanding of specific weakness classes and their potential impact on site integrity, or look up a product's vulnerability history to assess risk exposure before installation or upgrade. By centralizing this information, the page serves as a factual reference for security researchers, system administrators, and website owners who need to evaluate the current threat landscape surrounding this specific image gallery solution. The data is sourced from official disclosures and independent security reports, ensuring accuracy and relevance for those conducting due diligence on WordPress plugins. This approach allows stakeholders to make informed decisions based on historical security performance rather than relying on unverified claims.

Vendor: Photo Gallery Team

CVE IDTitleCVSSSeverityPublished
CVE-2026-9829 Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter CWE-89 6.5 Medium2026-06-06
CVE-2026-7048 Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute CWE-89 6.5 Medium2026-05-28
CVE-2026-1036 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion CWE-862 5.3 Medium2026-01-21
CVE-2025-2269 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter CWE-79 6.1 Medium2025-04-11
CVE-2024-9878 Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium2024-11-05
CVE-2024-5481 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function CWE-35 6.8 Medium2024-06-07
CVE-2024-5426 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG CWE-79 6.4 Medium2024-06-07
CVE-2024-2296 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG CWE-79 5.5 Medium2024-04-06
CVE-2024-0221 Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename CWE-22 9.1 Critical2024-02-05
CVE-2023-6924 Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget CWE-79 4.4 Medium2024-01-11
CVE-2022-1394 Photo Gallery < 1.6.4 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 -2022-06-06
CVE-2022-1282 Photo Gallery < 1.6.3 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-05-02
CVE-2022-1281 Photo Gallery < 1.6.3 - Unauthenticated SQL Injection CWE-89 9.8 -2022-05-02
CVE-2022-0169 Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection CWE-89 9.8 -2022-03-14
CVE-2021-25041 Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS) CWE-79 6.1 -2021-12-06
CVE-2021-24363 Photo Gallery < 1.5.75 - File Upload Path Traversal CWE-22 4.9 -2021-08-16
CVE-2021-24362 Photo Gallery < 1.5.75 - Stored Cross-Site Scripting via Uploaded SVG CWE-79 6.1 -2021-08-16
CVE-2021-24310 Photo Gallery < 1.5.67 - Authenticated Stored Cross-Site Scripting via Gallery Title CWE-79 4.8 -2021-06-01
CVE-2021-24291 Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS) CWE-79 6.1 -2021-05-14

All 19 known CVE vulnerabilities affecting Photo Gallery by 10Web – Mobile-Friendly Image Gallery with full Chinese analysis, references, and POCs where available.