Skip to main content

Vendor archive

tinywebgallery CVEs

Beta · best-effort

23 CVEs tagged to vendor tinywebgallery2 Critical, 3 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2023-53939

Published Dec 18, 2025

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attacke…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53922

Published Dec 17, 2025

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1440

Published Mar 26, 2025

The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-1439

Published Mar 26, 2025

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-1437

Published Mar 26, 2025

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-1341

Published Feb 29, 2024

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due t…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24870

Published Feb 5, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51690

Published Feb 1, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7069

Published Feb 1, 2024

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 du…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4775

Published Nov 13, 2023

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insuffici…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2021-24953

Published Mar 7, 2022

The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-S…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2631

Published Feb 3, 2020

TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_brow…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2931

Published Jan 9, 2020

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5014

Published Apr 25, 2018

The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16635

Published Nov 6, 2017

In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-privilege user accou…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2932

Published Apr 24, 2015

Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the selitems[] parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2930

Published Apr 24, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5347

Published Oct 9, 2012

TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3810

Published Sep 24, 2011

TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4958

Published Sep 18, 2007

Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) index.php, (2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4166

Published Aug 16, 2006

PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1802

Published Apr 18, 2006

Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1