CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2023-53939 MEDIUM

TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter

CVSS 5.1 EPSS 0.24% Dec 18, 2025
CVE-2023-53922 CRITICAL

TinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload

CVSS 9.3 EPSS 1.11% Dec 17, 2025
CVE-2025-1440 MEDIUM

Advanced iFrame <= 2024.5 - Unauthenticated Settings Update

CVSS 5.3 EPSS 0.29% Mar 26, 2025
CVE-2025-1437 MEDIUM

Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVSS 6.4 EPSS 0.26% Mar 26, 2025
CVE-2025-1439 MEDIUM

Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header

CVSS 6.4 EPSS 0.21% Mar 26, 2025
CVE-2024-1341 MEDIUM

Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVSS 5.4 EPSS 0.28% Feb 29, 2024
CVE-2024-24870 MEDIUM

WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS)

CVSS 6.5 EPSS 0.29% Feb 5, 2024
CVE-2023-51690 MEDIUM

WordPress Advanced iFrame Plugin <= 2023.8 is vulnerable to Cross Site Scripting (XSS)

CVSS 6.5 EPSS 0.31% Feb 1, 2024
CVE-2023-7069 MEDIUM

Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVSS 6.4 EPSS 0.31% Feb 1, 2024
CVE-2023-4775 MEDIUM

Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVSS 6.4 EPSS 0.55% Nov 13, 2023
CVE-2021-24953 MEDIUM

Advanced iFrame < 2022 - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 0.80% Mar 7, 2022
CVE-2013-2631 MEDIUM

TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the…

CVSS 5.3 EPSS 1.75% Feb 3, 2020
CVE-2012-2931 HIGH

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.

CVSS 7.2 EPSS 1.44% Jan 9, 2020
CVE-2014-5014 CRITICAL

The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters…

CVSS 9.8 EPSS 3.57% Apr 25, 2018
CVE-2017-16635 MEDIUM

In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-…

CVSS 5.4 EPSS 0.78% Nov 6, 2017
CVE-2012-2932 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 EPSS 1.21% Apr 24, 2015
CVE-2012-2930 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administ…

CVSS 6.8 EPSS 0.69% Apr 24, 2015
CVE-2012-5347 HIGH

TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) in…

CVSS 7.5 EPSS 4.36% Oct 9, 2012
CVE-2011-3810 MEDIUM

TinyWebGallery (TWG) 1.8.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in…

CVSS 5.0 EPSS 1.23% Sep 24, 2011
CVE-2009-1911 MEDIUM

Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and…

CVSS 6.8 EPSS 2.52% Jun 4, 2009
CVE-2007-4958 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI f…

CVSS 4.3 EPSS 1.03% Sep 18, 2007
CVE-2006-4166 HIGH

PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image paramete…

CVSS 7.5 EPSS 3.66% Aug 16, 2006
CVE-2006-1802 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_…

CVSS 4.3 EPSS 1.94% Apr 18, 2006

Showing 1 to 23 CVEs · page 1