Known CVE
10Web Photo Gallery < 1.5.55 - SQL Injection
WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the 'bwg_search_x' parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the 'bwg_search_x' parameter.
CVE-2021-24139
Critical2021CVSS 9.8CWE-89
cve2021 · wp · wp-plugin · sqli · photo-gallery · 10web · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website