Записи TinyWebGallery
23 опубликованных записей вендора tinywebgallery.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 13 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-20 Improper Input Validation1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-5014Эксплойта нет | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to tinywebgallery · wordpress flash uploader · CWE-77 | Критическая9,8 | — | 3,6 % | 25 апр. 2018 г. |
37Наблюдать | CVE-2023-53922Эксплойта нет | TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Uploadtinywebgallery · tinywebgallery · CWE-434 | Критическая9,3 | — | 1,1 % | 17 дек. 2025 г. |
31Наблюдать | CVE-2012-5347Proof of concept | TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctinywebgallery · tinywebgallery | Высокая7,5 | — | 4,4 % | 9 окт. 2012 г. |
31Наблюдать | CVE-2006-4166Proof of concept | PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL intinywebgallery · tinywebgallery | Высокая7,5 | — | 3,7 % | 16 авг. 2006 г. |
28Наблюдать | CVE-2009-1911Proof of concept | Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGalltinywebgallery · tinywebgallery · CWE-22 | Средняя6,8 | — | 2,5 % | 4 июн. 2009 г. |
28Наблюдать | CVE-2012-2931Эксплойта нет | PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the tinywebgallery · tinywebgallery · CWE-74 | Высокая7,2 | — | 1,4 % | 9 янв. 2020 г. |
27Наблюдать | CVE-2012-2930Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authenttinywebgallery · tinywebgallery · CWE-352 | Средняя6,8 | — | 0,7 % | 24 апр. 2015 г. |
24Наблюдать | CVE-2021-24953Эксплойта нет | Advanced iFrame < 2022 - Reflected Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Средняя6,1 | — | 0,8 % | 7 мар. 2022 г. |
22Наблюдать | CVE-2013-2631Эксплойта нет | TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive infortinywebgallery · tinywebgallery · CWE-200 | Средняя5,3 | — | 1,8 % | 3 февр. 2020 г. |
21Наблюдать | CVE-2017-16635Эксплойта нет | In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module.tinywebgallery · tinywebgallery · CWE-79 | Средняя5,4 | — | 0,8 % | 6 нояб. 2017 г. |
21Наблюдать | CVE-2023-4775Эксплойта нет | Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodetinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,6 % | 13 нояб. 2023 г. |
21Наблюдать | CVE-2023-7069Эксплойта нет | Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,3 % | 1 февр. 2024 г. |
21Наблюдать | CVE-2023-51690Эксплойта нет | WordPress Advanced iFrame Plugin <= 2023.8 is vulnerable to Cross Site Scripting (XSS)tinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,3 % | 1 февр. 2024 г. |
21Наблюдать | CVE-2025-1440Эксплойта нет | Advanced iFrame <= 2024.5 - Unauthenticated Settings Updatetinywebgallery · advanced iframe · CWE-20 | Средняя5,3 | — | 0,3 % | 26 мар. 2025 г. |
21Наблюдать | CVE-2024-24870Эксплойта нет | WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS)tinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,3 % | 5 февр. 2024 г. |
21Наблюдать | CVE-2024-1341Эксплойта нет | Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,3 % | 29 февр. 2024 г. |
21Наблюдать | CVE-2025-1437Эксплойта нет | Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingtinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,3 % | 26 мар. 2025 г. |
21Наблюдать | CVE-2025-1439Эксплойта нет | Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Headertinywebgallery · advanced iframe · CWE-79 | Средняя5,4 | — | 0,2 % | 26 мар. 2025 г. |
20Наблюдать | CVE-2011-3810Эксплойта нет | TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the intinywebgallery · tinywebgallery · CWE-200 | Средняя5,0 | — | 1,2 % | 23 сент. 2011 г. |
20Наблюдать | CVE-2023-53939Эксплойта нет | TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parametertinywebgallery · tinywebgallery · CWE-79 | Средняя5,1 | — | 0,2 % | 18 дек. 2025 г. |
18Наблюдать | CVE-2006-1802Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script otinywebgallery · tinywebgallery | Средняя4,3 | — | 1,9 % | 18 апр. 2006 г. |
17Наблюдать | CVE-2012-2932Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web scritinywebgallery · tinywebgallery · CWE-79 | Средняя4,3 | — | 1,2 % | 24 апр. 2015 г. |
17Наблюдать | CVE-2007-4958Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script ortinywebgallery · tinywebgallery · CWE-79 | Средняя4,3 | — | 1,0 % | 18 сент. 2007 г. |
- CVE-2014-501440В плане
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %tinywebgallery · wordpress flash uploader25 апр. 2018 г.
- CVE-2023-5392237Наблюдать
TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery17 дек. 2025 г.
- CVE-2012-534731Наблюдать
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunc
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %tinywebgallery · tinywebgallery9 окт. 2012 г.
- CVE-2006-416631Наблюдать
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %tinywebgallery · tinywebgallery16 авг. 2006 г.
- CVE-2009-191128Наблюдать
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGall
СредняяCVSS 6,8Proof of conceptEPSS 3 %tinywebgallery · tinywebgallery4 июн. 2009 г.
- CVE-2012-293128Наблюдать
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery9 янв. 2020 г.
- CVE-2012-293027Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authent
СредняяCVSS 6,8Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery24 апр. 2015 г.
- CVE-2021-2495324Наблюдать
Advanced iFrame < 2022 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tinywebgallery · advanced iframe7 мар. 2022 г.
- CVE-2013-263122Наблюдать
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive infor
СредняяCVSS 5,3Эксплойта нетEPSS 2 %tinywebgallery · tinywebgallery3 февр. 2020 г.
- CVE-2017-1663521Наблюдать
In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery6 нояб. 2017 г.
- CVE-2023-477521Наблюдать
Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 1 %tinywebgallery · advanced iframe13 нояб. 2023 г.
- CVE-2023-706921Наблюдать
Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe1 февр. 2024 г.
- CVE-2023-5169021Наблюдать
WordPress Advanced iFrame Plugin <= 2023.8 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe1 февр. 2024 г.
- CVE-2025-144021Наблюдать
Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
СредняяCVSS 5,3Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe26 мар. 2025 г.
- CVE-2024-2487021Наблюдать
WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe5 февр. 2024 г.
- CVE-2024-134121Наблюдать
Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe29 февр. 2024 г.
- CVE-2025-143721Наблюдать
Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe26 мар. 2025 г.
- CVE-2025-143921Наблюдать
Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tinywebgallery · advanced iframe26 мар. 2025 г.
- CVE-2011-381020Наблюдать
TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the in
СредняяCVSS 5,0Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery23 сент. 2011 г.
- CVE-2023-5393920Наблюдать
TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter
СредняяCVSS 5,1Эксплойта нетEPSS 0 %tinywebgallery · tinywebgallery18 дек. 2025 г.
- CVE-2006-180218Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script o
СредняяCVSS 4,3Proof of conceptEPSS 2 %tinywebgallery · tinywebgallery18 апр. 2006 г.
- CVE-2012-293217Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web scri
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery24 апр. 2015 г.
- CVE-2007-495817Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tinywebgallery · tinywebgallery18 сент. 2007 г.