tinywebgallery records
23 published records for vendor tinywebgallery.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 13%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-20 Improper Input Validation1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2014-5014No exploit | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to tinywebgallery · wordpress flash uploader · CWE-77 | Critical9.8 | — | 3.6% | Apr 25, 2018 |
37Monitor | CVE-2023-53922No exploit | TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Uploadtinywebgallery · tinywebgallery · CWE-434 | Critical9.3 | — | 1.1% | Dec 17, 2025 |
31Monitor | CVE-2012-5347Proof of concept | TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctinywebgallery · tinywebgallery | High7.5 | — | 4.4% | Oct 9, 2012 |
31Monitor | CVE-2006-4166Proof of concept | PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL intinywebgallery · tinywebgallery | High7.5 | — | 3.7% | Aug 16, 2006 |
28Monitor | CVE-2009-1911Proof of concept | Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGalltinywebgallery · tinywebgallery · CWE-22 | Medium6.8 | — | 2.5% | Jun 4, 2009 |
28Monitor | CVE-2012-2931No exploit | PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the tinywebgallery · tinywebgallery · CWE-74 | High7.2 | — | 1.4% | Jan 9, 2020 |
27Monitor | CVE-2012-2930No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authenttinywebgallery · tinywebgallery · CWE-352 | Medium6.8 | — | 0.7% | Apr 24, 2015 |
24Monitor | CVE-2021-24953No exploit | Advanced iFrame < 2022 - Reflected Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Medium6.1 | — | 0.8% | Mar 7, 2022 |
22Monitor | CVE-2013-2631No exploit | TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive infortinywebgallery · tinywebgallery · CWE-200 | Medium5.3 | — | 1.8% | Feb 3, 2020 |
21Monitor | CVE-2017-16635No exploit | In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module.tinywebgallery · tinywebgallery · CWE-79 | Medium5.4 | — | 0.8% | Nov 6, 2017 |
21Monitor | CVE-2023-4775No exploit | Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodetinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.6% | Nov 13, 2023 |
21Monitor | CVE-2023-7069No exploit | Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.3% | Feb 1, 2024 |
21Monitor | CVE-2023-51690No exploit | WordPress Advanced iFrame Plugin <= 2023.8 is vulnerable to Cross Site Scripting (XSS)tinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.3% | Feb 1, 2024 |
21Monitor | CVE-2025-1440No exploit | Advanced iFrame <= 2024.5 - Unauthenticated Settings Updatetinywebgallery · advanced iframe · CWE-20 | Medium5.3 | — | 0.3% | Mar 26, 2025 |
21Monitor | CVE-2024-24870No exploit | WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS)tinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.3% | Feb 5, 2024 |
21Monitor | CVE-2024-1341No exploit | Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.3% | Feb 29, 2024 |
21Monitor | CVE-2025-1437No exploit | Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.3% | Mar 26, 2025 |
21Monitor | CVE-2025-1439No exploit | Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Headertinywebgallery · advanced iframe · CWE-79 | Medium5.4 | — | 0.2% | Mar 26, 2025 |
20Monitor | CVE-2011-3810No exploit | TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the intinywebgallery · tinywebgallery · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
20Monitor | CVE-2023-53939No exploit | TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parametertinywebgallery · tinywebgallery · CWE-79 | Medium5.1 | — | 0.2% | Dec 18, 2025 |
18Monitor | CVE-2006-1802Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script otinywebgallery · tinywebgallery | Medium4.3 | — | 1.9% | Apr 18, 2006 |
17Monitor | CVE-2012-2932No exploit | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web scritinywebgallery · tinywebgallery · CWE-79 | Medium4.3 | — | 1.2% | Apr 24, 2015 |
17Monitor | CVE-2007-4958No exploit | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script ortinywebgallery · tinywebgallery · CWE-79 | Medium4.3 | — | 1.0% | Sep 18, 2007 |
- CVE-2014-501440Plan
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to
CriticalCVSS 9.8No exploitEPSS 4%tinywebgallery · wordpress flash uploaderApr 25, 2018
- CVE-2023-5392237Monitor
TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload
CriticalCVSS 9.3No exploitEPSS 1%tinywebgallery · tinywebgalleryDec 17, 2025
- CVE-2012-534731Monitor
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunc
HighCVSS 7.5Proof of conceptEPSS 4%tinywebgallery · tinywebgalleryOct 9, 2012
- CVE-2006-416631Monitor
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in
HighCVSS 7.5Proof of conceptEPSS 4%tinywebgallery · tinywebgalleryAug 16, 2006
- CVE-2009-191128Monitor
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGall
MediumCVSS 6.8Proof of conceptEPSS 3%tinywebgallery · tinywebgalleryJun 4, 2009
- CVE-2012-293128Monitor
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the
HighCVSS 7.2No exploitEPSS 1%tinywebgallery · tinywebgalleryJan 9, 2020
- CVE-2012-293027Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authent
MediumCVSS 6.8No exploitEPSS 1%tinywebgallery · tinywebgalleryApr 24, 2015
- CVE-2021-2495324Monitor
Advanced iFrame < 2022 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%tinywebgallery · advanced iframeMar 7, 2022
- CVE-2013-263122Monitor
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive infor
MediumCVSS 5.3No exploitEPSS 2%tinywebgallery · tinywebgalleryFeb 3, 2020
- CVE-2017-1663521Monitor
In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module.
MediumCVSS 5.4No exploitEPSS 1%tinywebgallery · tinywebgalleryNov 6, 2017
- CVE-2023-477521Monitor
Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 1%tinywebgallery · advanced iframeNov 13, 2023
- CVE-2023-706921Monitor
Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%tinywebgallery · advanced iframeFeb 1, 2024
- CVE-2023-5169021Monitor
WordPress Advanced iFrame Plugin <= 2023.8 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%tinywebgallery · advanced iframeFeb 1, 2024
- CVE-2025-144021Monitor
Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
MediumCVSS 5.3No exploitEPSS 0%tinywebgallery · advanced iframeMar 26, 2025
- CVE-2024-2487021Monitor
WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%tinywebgallery · advanced iframeFeb 5, 2024
- CVE-2024-134121Monitor
Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%tinywebgallery · advanced iframeFeb 29, 2024
- CVE-2025-143721Monitor
Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%tinywebgallery · advanced iframeMar 26, 2025
- CVE-2025-143921Monitor
Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header
MediumCVSS 5.4No exploitEPSS 0%tinywebgallery · advanced iframeMar 26, 2025
- CVE-2011-381020Monitor
TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in
MediumCVSS 5.0No exploitEPSS 1%tinywebgallery · tinywebgallerySep 23, 2011
- CVE-2023-5393920Monitor
TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter
MediumCVSS 5.1No exploitEPSS 0%tinywebgallery · tinywebgalleryDec 18, 2025
- CVE-2006-180218Monitor
Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script o
MediumCVSS 4.3Proof of conceptEPSS 2%tinywebgallery · tinywebgalleryApr 18, 2006
- CVE-2012-293217Monitor
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web scri
MediumCVSS 4.3No exploitEPSS 1%tinywebgallery · tinywebgalleryApr 24, 2015
- CVE-2007-495817Monitor
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3No exploitEPSS 1%tinywebgallery · tinywebgallerySep 18, 2007