CVE-2016-10940: Zm-Gallery Project Zm-Gallery
High severity, CVSS 7.2. EPSS: 5.6% chance of exploitation in the next 30 days.
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Affected products
- Zm-Gallery Project Zm-Gallery: version 1.0 only
Published 2019-09-13. Last modified 2026-06-17.