Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-53939 TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the … Tinywebgallery No fix yet Fix from $1,6002025-12-18 CRITICAL 9.8 CVE-2023-53922 TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload … Tinywebgallery Mitigation only Fix from $2,3002025-12-17 MEDIUM 5.4 CVE-2025-1439 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up… Advanced Iframe 2025.0+ Fix from $1,6002025-03-26 MEDIUM 5.3 CVE-2025-1440 The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all ve… Advanced Iframe 2025.0+ Fix from $1,6002025-03-26 MEDIUM 5.4 CVE-2025-1437 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up… Advanced Iframe 2025.3+ Fix from $1,6002025-03-26 MEDIUM 5.4 CVE-2024-1341 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up t… Advanced Iframe 2024.2+ Fix from $1,6002024-02-29 MEDIUM 5.4 CVE-2024-24870 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored X… Advanced Iframe 2024.0+ Fix from $1,6002024-02-05 MEDIUM 5.4 CVE-2023-51690 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue af… Advanced Iframe after 2023.8 Fix from $1,6002024-02-01 MEDIUM 5.4 CVE-2023-7069 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up… Advanced Iframe 2024.0+ Fix from $1,6002024-02-01 MEDIUM 5.4 CVE-2023-4775 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and incl… Advanced Iframe after 2023.8 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2021-24953 The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, … Advanced Iframe 2022+ Fix from $1,6002022-03-07 MEDIUM 5.3 CVE-2013-2631 TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information th… Tinywebgallery after 1.8.9 Fix from $1,6002020-02-03 HIGH 7.2 CVE-2012-2931 PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.… Tinywebgallery 1.8.8+ Fix from $1,9502020-01-09 CRITICAL 9.8 CVE-2014-5014 The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid c… Wordpress Flash Uploader 3.1.3+ Fix from $2,3002018-04-25 MEDIUM 5.4 CVE-2017-16635 In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers… Tinywebgallery Mitigation only Fix from $1,6002017-11-06 MEDIUM 6.8 CVE-2012-2930 Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication o… Tinywebgallery after 1.8.6 Fix from $1,6002015-04-24 HIGH 7.5 CVE-2012-5347 TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc… Tinywebgallery No fix yet Fix from $1,9502012-10-09 MEDIUM 5.0 CVE-2011-3810 TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio… Tinywebgallery Mitigation only Fix from $1,6002011-09-24 MEDIUM 6.8 CVE-2009-1911 Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG)… Tinywebgallery after 2.3.2 Fix from $1,6002009-06-04 HIGH 7.5 CVE-2006-4166 PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the imag… Tinywebgallery after 1.5 Fix from $1,9502006-08-16