CVE-2024-29810: 10web Photo Gallery

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

Affected products

  • 10web Photo Gallery: before 1.8.22 (fixed in 1.8.22)

Published 2024-03-26. Last modified 2026-06-17.