Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2023-53939
TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the …
Tinywebgallery
No fix yet
CRITICAL 9.8
CVE-2023-53922
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload …
Tinywebgallery
Mitigation only
MEDIUM 5.4
CVE-2025-1439
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up…
Advanced Iframe
2025.0+
MEDIUM 5.3
CVE-2025-1440
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all ve…
Advanced Iframe
2025.0+
MEDIUM 5.4
CVE-2025-1437
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up…
Advanced Iframe
2025.3+
MEDIUM 5.4
CVE-2024-1341
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up t…
Advanced Iframe
2024.2+
MEDIUM 5.4
CVE-2024-24870
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored X…
Advanced Iframe
2024.0+
MEDIUM 5.4
CVE-2023-51690
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue af…
Advanced Iframe
after 2023.8
MEDIUM 5.4
CVE-2023-7069
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up…
Advanced Iframe
2024.0+
MEDIUM 5.4
CVE-2023-4775
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and incl…
Advanced Iframe
after 2023.8
MEDIUM 6.1
CVE-2021-24953
The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, …
Advanced Iframe
2022+
MEDIUM 5.3
CVE-2013-2631
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information th…
Tinywebgallery
after 1.8.9
HIGH 7.2
CVE-2012-2931
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.…
Tinywebgallery
1.8.8+
CRITICAL 9.8
CVE-2014-5014
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid c…
Wordpress Flash Uploader
3.1.3+
MEDIUM 5.4
CVE-2017-16635
In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers…
Tinywebgallery
Mitigation only
MEDIUM 6.8
CVE-2012-2930
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication o…
Tinywebgallery
after 1.8.6
HIGH 7.5
CVE-2012-5347
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc…
Tinywebgallery
No fix yet
MEDIUM 5.0
CVE-2011-3810
TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio…
Tinywebgallery
Mitigation only
MEDIUM 6.8
CVE-2009-1911
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG)…
Tinywebgallery
after 2.3.2
HIGH 7.5
CVE-2006-4166
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the imag…
Tinywebgallery
after 1.5