Skip to content
Noroxi

tinywebgallery records

23 published records for vendor tinywebgallery.

All records

23 records
  • The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to

    CriticalCVSS 9.8No exploitEPSS 4%

    tinywebgallery · wordpress flash uploaderApr 25, 2018

  • TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload

    CriticalCVSS 9.3No exploitEPSS 1%

    tinywebgallery · tinywebgalleryDec 17, 2025

  • CVE-2012-5347
    31Monitor

    TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunc

    HighCVSS 7.5Proof of conceptEPSS 4%

    tinywebgallery · tinywebgalleryOct 9, 2012

  • CVE-2006-4166
    31Monitor

    PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in

    HighCVSS 7.5Proof of conceptEPSS 4%

    tinywebgallery · tinywebgalleryAug 16, 2006

  • CVE-2009-1911
    28Monitor

    Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGall

    MediumCVSS 6.8Proof of conceptEPSS 3%

    tinywebgallery · tinywebgalleryJun 4, 2009

  • CVE-2012-2931
    28Monitor

    PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the

    HighCVSS 7.2No exploitEPSS 1%

    tinywebgallery · tinywebgalleryJan 9, 2020

  • CVE-2012-2930
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authent

    MediumCVSS 6.8No exploitEPSS 1%

    tinywebgallery · tinywebgalleryApr 24, 2015

  • Advanced iFrame < 2022 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    tinywebgallery · advanced iframeMar 7, 2022

  • CVE-2013-2631
    22Monitor

    TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive infor

    MediumCVSS 5.3No exploitEPSS 2%

    tinywebgallery · tinywebgalleryFeb 3, 2020

  • In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module.

    MediumCVSS 5.4No exploitEPSS 1%

    tinywebgallery · tinywebgalleryNov 6, 2017

  • CVE-2023-4775
    21Monitor

    Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    tinywebgallery · advanced iframeNov 13, 2023

  • CVE-2023-7069
    21Monitor

    Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    tinywebgallery · advanced iframeFeb 1, 2024

  • WordPress Advanced iFrame Plugin <= 2023.8 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    tinywebgallery · advanced iframeFeb 1, 2024

  • CVE-2025-1440
    21Monitor

    Advanced iFrame <= 2024.5 - Unauthenticated Settings Update

    MediumCVSS 5.3No exploitEPSS 0%

    tinywebgallery · advanced iframeMar 26, 2025

  • WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    tinywebgallery · advanced iframeFeb 5, 2024

  • CVE-2024-1341
    21Monitor

    Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    tinywebgallery · advanced iframeFeb 29, 2024

  • CVE-2025-1437
    21Monitor

    Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    tinywebgallery · advanced iframeMar 26, 2025

  • CVE-2025-1439
    21Monitor

    Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header

    MediumCVSS 5.4No exploitEPSS 0%

    tinywebgallery · advanced iframeMar 26, 2025

  • CVE-2011-3810
    20Monitor

    TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in

    MediumCVSS 5.0No exploitEPSS 1%

    tinywebgallery · tinywebgallerySep 23, 2011

  • TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter

    MediumCVSS 5.1No exploitEPSS 0%

    tinywebgallery · tinywebgalleryDec 18, 2025

  • CVE-2006-1802
    18Monitor

    Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script o

    MediumCVSS 4.3Proof of conceptEPSS 2%

    tinywebgallery · tinywebgalleryApr 18, 2006

  • CVE-2012-2932
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web scri

    MediumCVSS 4.3No exploitEPSS 1%

    tinywebgallery · tinywebgalleryApr 24, 2015

  • CVE-2007-4958
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3No exploitEPSS 1%

    tinywebgallery · tinywebgallerySep 18, 2007