Cross-Site Scripting
39 records60%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 65 vulnerability records associated with Photo Gallery by 10Web – Mobile-Friendly Image Gallery, published between 2014 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 2 | |
| 2015 | 5 | |
| 2017 | 4 | |
| 2019 | 6 | |
| 2020 | 2 | |
| 2021 | 9 | |
| 2022 | 11 | |
| 2023 | 3 | |
| 2024 | 14 | |
| 2025 | 4 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 6 | 9.2% |
| High | 6 | 9.2% |
| Medium | 51 | 78.5% |
| Low | 1 | 1.5% |
| Informational | 1 | 1.5% |
First: 2014. Latest: 2025.
First: 2015. Latest: 2026.
First: 2017. Latest: 2024.
First: 2023. Latest: 2026.
First: 2014. Latest: 2026.
First: 2019. Latest: 2022.
First: 2015. Latest: 2015.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.8.421.8.411.8.381.8.371.8.391.8.351.8.341.8.331.8.311.8.291.8.281.8.241.8.261.8.211.8.221.8.201.8.191.8.161.8.151.8.31.8.81.8.11.7.11.6.91.6.81.6.71.6.41.6.31.6.01.5.791.5.751.5.671.5.691.5.681.5.551.5.461.5.351.5.311.5.251.5.231.3.671.3.511.3.431.3.381.2.131.2.61.2.111.2.81.1.311.2.42Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.8.41 | Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter | June 5, 2026 | 1.8.42 | Medium |
*-1.8.41 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 - Authenticated (Contributor+) SQL Injection | June 4, 2026 | 1.8.42 | Medium |
*-1.8.40 | Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute | May 27, 2026 | 1.8.41 | Medium |
*-1.8.37 | Photo Gallery by 10Web <= 1.8.37 - Cross-Site Request Forgery | February 8, 2026 | 1.8.38 | Medium |
*-1.8.36 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion | January 21, 2026 | 1.8.37 | Medium |
*-1.8.38 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.38 - Authenticated (Editor+) Stored Cross-Site Scripting | December 25, 2025 | 1.8.39 | Medium |
*-1.8.34 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter | April 11, 2025 | 1.8.35 | Medium |
*-1.8.33 | Photo Gallery by 10Web <= 1.8.33 - Unauthenticated Stored Cross-Site Scripting | March 10, 2025 | 1.8.34 | Medium |
*-1.8.32 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.32 - Authenticated (Admin+) Stored Cross-Site Scripting | March 2, 2025 | 1.8.33 | Medium |
*-1.8.30 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.30 - Authenticated (Admin+) Stored Cross-Site Scripting | November 14, 2024 | 1.8.31 | Medium |
*-1.8.30 | Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting | November 4, 2024 | 1.8.31 | Medium |
*-1.8.28 | Photo Gallery by 10Web <= 1.8.28 - Authenticated (Administrator+) Stored Cross-Site Scripting | October 3, 2024 | 1.8.29 | Medium |
*-1.8.27 | Photo Gallery by 10Web <= 1.8.27 - Authenticated (Administrator+) Stored Cross-Site Scripting | September 23, 2024 | 1.8.28 | Medium |
*-1.8.23 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function | June 6, 2024 | 1.8.24 | Medium |
*-1.8.23 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG | June 6, 2024 | 1.8.24 | Medium |
*-1.8.25 | Photo Gallery by 10Web <= 1.8.25 - Missing Authorization to Notice Dismissal | May 27, 2024 | 1.8.26 | Medium |
*-1.8.20 | Photo Gallery by 10Web <= 1.8.20 - Missing Authorization | April 25, 2024 | 1.8.21 | Medium |
*-1.8.21 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG | April 5, 2024 | 1.8.22 | Medium |
*-1.8.21 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'thumb_url' | March 26, 2024 | 1.8.22 | Medium |
*-1.8.21 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'image_id' | March 26, 2024 | 1.8.22 | Medium |
*-1.8.21 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'current_url' | March 26, 2024 | 1.8.22 | Medium |
*-1.8.21 | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'image_url' | March 26, 2024 | 1.8.22 | Medium |
*-1.8.19 | Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename | January 19, 2024 | 1.8.20 | Critical |
*-1.8.18 | Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget | December 21, 2023 | 1.8.19 | Medium |
[*, 1.8.16) | Photo Gallery <= 1.8.15 - Missing Authorization | June 2, 2023 | 1.8.16 | Medium |
Selected source records
Published: June 5, 2026
Published: June 4, 2026
Published: May 27, 2026
Published: February 8, 2026
Published: January 21, 2026
Published: December 25, 2025
Published: April 11, 2025
Published: March 10, 2025
Published: January 12, 2015
Published: May 15, 2020
Published: July 26, 2019
Published: September 8, 2019
Published: February 15, 2022
Published: January 19, 2024
Published: May 2, 2017
Published: April 11, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.