Cross-Site Scripting
39 records60%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 65 vulnerability records associated with Photo Gallery by 10Web – Mobile-Friendly Image Gallery, published between 2014 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 2 | |
| 2015 | 5 | |
| 2017 | 4 | |
| 2019 | 6 | |
| 2020 | 2 | |
| 2021 | 9 | |
| 2022 | 11 | |
| 2023 | 3 | |
| 2024 | 14 | |
| 2025 | 4 | |
| 2026 | 5 |
| Severity | Records | Share |
|---|---|---|
| Critical | 6 | 9.2% |
| High | 6 | 9.2% |
| Medium | 51 | 78.5% |
| Low | 1 | 1.5% |
| Informational | 1 | 1.5% |
First: 2014. Latest: 2025.
First: 2015. Latest: 2026.
First: 2017. Latest: 2024.
First: 2023. Latest: 2026.
First: 2014. Latest: 2026.
First: 2019. Latest: 2022.
First: 2015. Latest: 2015.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.8.421.8.411.8.381.8.371.8.391.8.351.8.341.8.331.8.311.8.291.8.281.8.241.8.261.8.211.8.221.8.201.8.191.8.161.8.151.8.31.8.81.8.11.7.11.6.91.6.81.6.71.6.41.6.31.6.01.5.791.5.751.5.671.5.691.5.681.5.551.5.461.5.351.5.311.5.251.5.231.3.671.3.511.3.431.3.381.2.131.2.61.2.111.2.81.1.311.2.42Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.5.34 | Photo Gallery by 10Web <= 1.5.34 - Cross-Site Scripting | September 8, 2019 | 1.5.35 | Medium |
[*, 1.5.31) | Photo Gallery by 10Web <= 1.5.30 - SQL Injection | July 26, 2019 | 1.5.31 | Critical |
*-1.5.24 | Photo Gallery by 10Web <= 1.5.24 - Authenticated Local File Inclusion | May 15, 2019 | 1.5.25 | Medium |
*-1.5.22 | Photo Gallery by 10Web <= 1.5.22 - Authenticated Cross-Site Scripting | May 13, 2019 | 1.5.23 | Medium |
[*, 1.3.67) | Photo Gallery by 10Web <= 1.3.66 - Cross-Site Scripting | December 14, 2017 | 1.3.67 | Medium |
[*, 1.3.51) | Photo Gallery by 10Web <= 1.3.50 - Authenticated SQL Injection via tag_id Parameter | August 20, 2017 | 1.3.51 | High |
[*, 1.3.43) | Photo Gallery by 10Web < 1.3.43 - Authenticated Path Traversal | June 16, 2017 | 1.3.43 | Medium |
[*, 1.3.38) | Photo Gallery by 10Web <= 1.3.37 - Authenticated SQL Injection | May 2, 2017 | 1.3.38 | High |
[*, 1.2.13) | Photo Gallery by 10Web <= 1.2.12 - Authenticated Cross-Site Scripting | March 13, 2015 | 1.2.13 | Medium |
[*, 1.2.6) | Photo Gallery by 10Web <= 1.2.5 - Unrestricted File Upload | February 12, 2015 | 1.2.6 | High |
[*, 1.2.11) | Photo Gallery by 10Web <= 1.2.10 - Authenticated Cross-Site Scripting | January 28, 2015 | 1.2.11 | Medium |
[*, 1.2.11) | Photo Gallery by 10Web <= 1.2.10 - Authenticated SQL Injection via asc_or_desc Parameter | January 23, 2015 | 1.2.11 | High |
[*, 1.2.8) | Photo Gallery by 10Web <= 1.2.7 - Unauthenticated Blind SQL Injection via order_by Parameter | January 12, 2015 | 1.2.8 | Critical |
*-1.1.30 | Photo Gallery by 10Web <= 1.1.30 - Reflected Cross-Site Scripting | October 1, 2014 | 1.1.31 | Low |
[*, 1.2.42) | Photo Gallery by 10Web <= 1.2.41 - Cross-Site Request Forgery | May 7, 2014 | 1.2.42 | High |
Selected source records
Published: June 5, 2026
Published: June 4, 2026
Published: May 27, 2026
Published: February 8, 2026
Published: January 21, 2026
Published: December 25, 2025
Published: April 11, 2025
Published: March 10, 2025
Published: January 12, 2015
Published: May 15, 2020
Published: July 26, 2019
Published: September 8, 2019
Published: February 15, 2022
Published: January 19, 2024
Published: May 2, 2017
Published: April 11, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.