Filtered by vendor 10web
Subscriptions
Total
110 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-16117 | 1 10web | 1 Photo Gallery | 2024-11-21 | 6.1 Medium |
| Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php. | ||||
| CVE-2019-14798 | 1 10web | 1 Photo Gallery | 2024-11-21 | N/A |
| The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter. | ||||
| CVE-2019-14797 | 1 10web | 1 Photo Gallery | 2024-11-21 | N/A |
| The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. | ||||
| CVE-2019-14313 | 1 10web | 1 Photo Gallery | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php. | ||||
| CVE-2019-11590 | 1 10web | 1 Form Maker | 2024-11-21 | N/A |
| The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized. | ||||
| CVE-2019-10866 | 1 10web | 1 Form Maker | 2024-11-21 | N/A |
| In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter. | ||||
| CVE-2015-9380 | 1 10web | 1 Photo Gallery | 2024-11-21 | N/A |
| The photo-gallery plugin before 1.2.42 for WordPress has CSRF. | ||||
| CVE-2015-2324 | 1 10web | 1 Photo Gallery | 2024-11-21 | N/A |
| Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors. | ||||
| CVE-2015-1394 | 1 10web | 1 Photo Gallery | 2024-11-21 | 5.4 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php. | ||||
| CVE-2024-8283 | 1 10web | 1 Slider | 2024-10-07 | 4.8 Medium |
| The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
ReportizFlow