Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tinywebgallery MEDIUM 5.4
CVE-2023-53939

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the …

No fix yet
Fix from $1,600 2025-12-18
Tinywebgallery CRITICAL 9.8
CVE-2023-53922

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload …

Mitigation only
Fix from $2,300 2025-12-17
Advanced Iframe MEDIUM 5.4
CVE-2025-1439

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up…

Fix: 2025.0+
Fix from $1,600 2025-03-26
Advanced Iframe MEDIUM 5.3
CVE-2025-1440

The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all ve…

Fix: 2025.0+
Fix from $1,600 2025-03-26
Advanced Iframe MEDIUM 5.4
CVE-2025-1437

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up…

Fix: 2025.3+
Fix from $1,600 2025-03-26
Advanced Iframe MEDIUM 5.4
CVE-2024-1341

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up t…

Fix: 2024.2+
Fix from $1,600 2024-02-29
Advanced Iframe MEDIUM 5.4
CVE-2024-24870

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored X…

Fix: 2024.0+
Fix from $1,600 2024-02-05
Advanced Iframe MEDIUM 5.4
CVE-2023-51690

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue af…

Fix: after 2023.8
Fix from $1,600 2024-02-01
Advanced Iframe MEDIUM 5.4
CVE-2023-7069

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up…

Fix: 2024.0+
Fix from $1,600 2024-02-01
Advanced Iframe MEDIUM 5.4
CVE-2023-4775

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and incl…

Fix: after 2023.8
Fix from $1,600 2023-11-13
Advanced Iframe MEDIUM 6.1
CVE-2021-24953

The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, …

Fix: 2022+
Fix from $1,600 2022-03-07
Tinywebgallery MEDIUM 5.3
CVE-2013-2631

TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information th…

Fix: after 1.8.9
Fix from $1,600 2020-02-03
Tinywebgallery HIGH 7.2
CVE-2012-2931

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.…

Fix: 1.8.8+
Fix from $1,950 2020-01-09
Wordpress Flash Uploader CRITICAL 9.8
CVE-2014-5014

The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid c…

Fix: 3.1.3+
Fix from $2,300 2018-04-25
Tinywebgallery MEDIUM 5.4
CVE-2017-16635

In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers…

Mitigation only
Fix from $1,600 2017-11-06
Tinywebgallery MEDIUM 6.8
CVE-2012-2930

Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication o…

Fix: after 1.8.6
Fix from $1,600 2015-04-24
Tinywebgallery HIGH 7.5
CVE-2012-5347

TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc…

No fix yet
Fix from $1,950 2012-10-09
Tinywebgallery MEDIUM 5.0
CVE-2011-3810

TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatio…

Mitigation only
Fix from $1,600 2011-09-24
Tinywebgallery MEDIUM 6.8
CVE-2009-1911

Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG)…

Fix: after 2.3.2
Fix from $1,600 2009-06-04
Tinywebgallery HIGH 7.5
CVE-2006-4166

PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the imag…

Fix: after 1.5
Fix from $1,950 2006-08-16