CVE-2012-2931: Tinywebgallery

High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.

PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.

Affected products

Published 2020-01-09. Last modified 2026-06-16.