CVE-2013-2631: Tinywebgallery

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.

Affected products

Published 2020-02-03. Last modified 2026-06-16.