Vulnerabilities (CVE)

Filtered by vendor 10web Subscribe
Filtered by product Photo Gallery
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1055 1 10web 1 Photo Gallery 2019-07-08 7.5 HIGH N/A
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.
CVE-2015-1393 1 10web 1 Photo Gallery 2019-07-08 6.5 MEDIUM N/A
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.