CVE-2012-2931: Tinywebgallery
High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
Affected products
- Tinywebgallery Tinywebgallery: before 1.8.8 (fixed in 1.8.8)
Published 2020-01-09. Last modified 2026-06-16.