Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Photo Gallery Team — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting Photo Gallery Team. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Photo Gallery Team develops image management and sharing software with a core use case of organizing and displaying visual content. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure file handling. The team has addressed multiple CVEs, including critical flaws allowing arbitrary code execution through manipulated image files. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests ongoing challenges in secure coding practices, particularly around file processing and user input sanitization.

CVE IDTitleCVSSSeverityPublished
CVE-2023-33995 WordPress Photo Gallery by 10Web plugin <= 1.8.15 - Broken Access Control vulnerability — Photo Gallery by 10WebCWE-862 4.3 Medium2024-12-13
CVE-2024-37442 WordPress Photo Gallery by Ays – Responsive Image Gallery plugin < 5.7.1 - HTML Injection vulnerability — Photo Gallery by AysCWE-74 3.8 Low2024-07-09
CVE-2024-35628 WordPress Photo Gallery by 10Web plugin <= 1.8.25 - Broken Access Control vulnerability — Photo Gallery by 10WebCWE-862 4.3 Medium2024-06-11
CVE-2024-33586 WordPress Photo Gallery by 10Web plugin <= 1.8.20 - Broken Access Control vulnerability — Photo Gallery by 10WebCWE-862 5.3 Medium2024-04-29
CVE-2024-32583 WordPress Photo Gallery by 10Web plugin <= 1.8.21 - Reflected Cross Site Scripting (XSS) vulnerability — Photo Gallery by 10WebCWE-79 7.1 High2024-04-18
CVE-2024-29919 WordPress Photo Gallery by Ays Plugin <=5.5.2 - Reflected Cross Site Scripting (XSS) vulnerability — Photo Gallery by AysCWE-79 7.1 High2024-03-27
CVE-2023-39917 WordPress Photo Gallery by Ays Plugin <= 5.2.6 is vulnerable to Cross Site Request Forgery (CSRF) — Photo Gallery by Ays – Responsive Image GalleryCWE-352 4.3 Medium2023-10-03
CVE-2023-32107 WordPress Photo Gallery by Ays Plugin <= 5.1.3 is vulnerable to Cross Site Scripting (XSS) — Photo Gallery by Ays – Responsive Image GalleryCWE-79 7.1 High2023-08-18
CVE-2021-24291 Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS) — Photo Gallery by 10Web – Mobile-Friendly Image GalleryCWE-79 6.1 -2021-05-14

This page lists every published CVE security advisory associated with Photo Gallery Team. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.