← Back

10web

103 CVEs • 15 products

Products (15)

Click to collapse
Toggle
Photo Gallery
photo_gallery
Form Maker
form_maker
Slider
slider
Seo
seo
10webanalytics
10web Booster
10web_booster
10websocial
Spidercalendar
spidercalendar
Sliderby10web
sliderby10web
Ai Assistant
ai_assistant
Spidercontacts
spidercontacts

CVEs (103)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
110web
1Photo Gallery
May 13, 2026
Aug 21, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGC...Show more
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.Show less
110web
1Photo Gallery
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the gal...Show more
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.Show less
110web
1Photo Gallery
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.