← WordPress Vulnerabilities
WordPress security by component

Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Photo Gallery by 10Web – Mobile-Friendly Image Gallery is a WordPress component with 58 published CVE records in this archive. The latest tracked vulnerability was published Jun 06, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: photo-gallery

CVE-2026-9829: Photo Gallery by 10Web – Mobile-Friendly Image Gallery: SQL injection

Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.8.41.

PublishedJun 06, 2026
Known safe version> 1.8.41
Safe version
Jun 06, 2026 CVE-2026-9829
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: SQL injection
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.8.41.
> 1.8.41
CVE6.5
NVDPending
Jun 04, 2026 CVE-2026-49771
Photo Gallery by 10Web: SQL injection
Photo Gallery by 10Web is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.8.41.
1.8.42
CVE7.6
NVDPending
May 28, 2026 CVE-2026-7048
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: SQL injection
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by SQL injection. Exploitation requires at least contributor-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.8.40.
> 1.8.40
CVE6.5
NVDPending
Mar 13, 2026 CVE-2026-32330
Photo Gallery by 10Web: Cross-site request forgery
Photo Gallery by 10Web is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Feb 19, 2026 CVE-2026-27360
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Jan 22, 2026 CVE-2026-1036
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: A security weakness
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 15, 2025 CVE-2024-8670
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Apr 12, 2025 CVE-2025-2269
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Mar 31, 2025 CVE-2025-0613
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Mar 24, 2025 CVE-2024-13124
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Dec 13, 2024 CVE-2023-33995
Photo Gallery by 10Web: A security weakness
Photo Gallery by 10Web is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 29, 2024 CVE-2024-10704
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Nov 05, 2024 CVE-2024-9878
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Oct 09, 2024 CVE-2024-5968
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Oct 06, 2024 CVE-2024-44043
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Jun 11, 2024 CVE-2024-35628
Photo Gallery by 10Web: A security weakness
Photo Gallery by 10Web is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Jun 07, 2024 CVE-2024-5481
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Filesystem traversal
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.8
NVD8.8
Jun 07, 2024 CVE-2024-5426
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 29, 2024 CVE-2024-33586
Photo Gallery by 10Web: A security weakness
Photo Gallery by 10Web is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Apr 18, 2024 CVE-2024-32583
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Apr 06, 2024 CVE-2024-2296
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Mar 26, 2024 CVE-2024-29833
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 26, 2024 CVE-2024-29832
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 26, 2024 CVE-2024-29810
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 26, 2024 CVE-2024-29809
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 26, 2024 CVE-2024-29808
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Feb 05, 2024 CVE-2024-0221
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Filesystem traversal
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.1
NVD7.2
Jan 11, 2024 CVE-2023-6924
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jun 12, 2023 CVE-2023-2568
Photo Gallery by Ays: Cross-site scripting
Photo Gallery by Ays is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 07, 2023 CVE-2021-46889
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Apr 17, 2023 CVE-2023-1427
Photo Gallery by 10Web: Filesystem traversal
Photo Gallery by 10Web is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD4.9
Dec 19, 2022 CVE-2022-4058
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Nov 29, 2022 CVE-2021-31693
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 08, 2022 CVE-2022-1394
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 02, 2022 CVE-2022-1282
Photo Gallery by 10Web: A security weakness
Photo Gallery by 10Web is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.1
NVD6.1
May 02, 2022 CVE-2022-1281
Photo Gallery: SQL injection
Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Mar 14, 2022 CVE-2022-0169
Photo Gallery by 10Web: SQL injection
Photo Gallery by 10Web is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Dec 06, 2021 CVE-2021-25041
Photo Gallery by 10Web: Cross-site scripting
Photo Gallery by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 16, 2021 CVE-2021-24363
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Filesystem traversal
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD4.9
Aug 16, 2021 CVE-2021-24362
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 02, 2021 CVE-2021-24462
get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery: SQL injection
get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Jun 01, 2021 CVE-2021-24310
Photo Gallery by 10Web - Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web - Mobile-Friendly Image Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 14, 2021 CVE-2021-24291
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Cross-site scripting
Photo Gallery by 10Web – Mobile-Friendly Image Gallery is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 18, 2021 CVE-2021-24139
Photo Gallery (10Web Photo Gallery): SQL injection
Photo Gallery (10Web Photo Gallery) is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Feb 25, 2020 CVE-2020-9335
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Feb 08, 2020 CVE-2015-1394
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Sep 08, 2019 CVE-2019-16119
Photo Gallery: SQL injection
Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Sep 08, 2019 CVE-2019-16118
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 08, 2019 CVE-2019-16117
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 30, 2019 CVE-2015-9380
Photo Gallery: Cross-site request forgery
Photo Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Aug 09, 2019 CVE-2019-14798
Photo Gallery: Filesystem traversal
Photo Gallery is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD4.9
Aug 09, 2019 CVE-2019-14797
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jul 30, 2019 CVE-2019-14313
Photo Gallery: SQL injection
Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Feb 19, 2018 CVE-2015-2324
Photo Gallery: Cross-site scripting
Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 28, 2017 CVE-2014-9312
Photo Gallery: A security weakness
Photo Gallery is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Aug 21, 2017 CVE-2017-12977
Photo Gallery: SQL injection
Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Feb 02, 2015 CVE-2015-1393
Photo Gallery: SQL injection
Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD6.5
Jan 16, 2015 CVE-2015-1055
Photo Gallery: SQL injection
Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5