CVEs we hold for Photo
Records whose assigning authority named Photo as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-57945PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{uid} Endpointphotoprism
CVE-2026-4429OSM <= 6.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attributephotoweblog OSM – OpenStreetMap
CVE-2026-43893exiftool-vendored: Argument injection via newline characters in tag namesphotostructure exiftool-vendored.js
CVE-2026-12865Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged ParametersUnknown Photo Gallery by 10Web
CVE-2025-62762WordPress SMTP Mail plugin <= 1.3.51 - Cross Site Request Forgery (CSRF) vulnerabilityphotoboxone SMTP Mail
CVE-2025-57964WordPress Library Bookshelves Plugin <= 5.11 - Cross Site Scripting (XSS) Vulnerabilityphotonicgnostic Library Bookshelves
CVE-2025-31766WordPress PhotoShelter for Photographers Blog Feed plugin <= 1.5.7 - Cross Site Scripting (XSS) vulnerabilityPhotoShelter for Photographers Blog Feed Plugin
CVE-2024-8991OSM <= 6.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via osm_map and osm_map_v3 Shortcodesphotoweblog OSM – OpenStreetMap
CVE-2024-6393NextGEN Gallery < 3.59.5 - Admin+ Stored XSSUnknown Photo Gallery, Sliders, Proofing and Themes
CVE-2024-5442NextGEN Gallery < 3.59.3 - Admin+ Stored XSSUnknown Photo Gallery, Sliders, Proofing and Themes
CVE-2024-52453WordPress Library Bookshelves plugin <= 5.8 - Reflected Cross Site Scripting (XSS) vulnerabilityphotonicgnostic Library Bookshelves
CVE-2024-49610WordPress photokit plugin <= 1.0 - Arbitrary File Upload vulnerabilityphotokiteditor photokit
CVE-2024-37442WordPress Photo Gallery by Ays – Responsive Image Gallery plugin < 5.7.1 - HTML Injection vulnerabilityPhoto Gallery by Ays
CVE-2024-3604OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injectionphotoweblog OSM – OpenStreetMap
CVE-2024-3603OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodephotoweblog OSM – OpenStreetMap
CVE-2024-35628WordPress Photo Gallery by 10Web plugin <= 1.8.25 - Broken Access Control vulnerabilityPhoto Gallery by 10Web
CVE-2024-33586WordPress Photo Gallery by 10Web plugin <= 1.8.20 - Broken Access Control vulnerabilityPhoto Gallery by 10Web
CVE-2024-32583WordPress Photo Gallery by 10Web plugin <= 1.8.21 - Reflected Cross Site Scripting (XSS) vulnerabilityPhoto Gallery by 10Web
CVE-2024-29919WordPress Photo Gallery by Ays Plugin <=5.5.2 - Reflected Cross Site Scripting (XSS) vulnerabilityPhoto Gallery by Ays
CVE-2024-25914WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF)Photoboxone SMTP Mail
CVE-2024-1487Photos and Files Contest Gallery < 21.3.1 - Author+ Stored Cross Site ScriptingUnknown Photos and Files Contest Gallery
CVE-2024-13822Total Contest Lite <= 2.8.1 - Reflected XSSUnknown Photo Contest | Competition | Video Contest
CVE-2024-13464Library Bookshelves <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scriptingphotonicgnostic Library Bookshelves
CVE-2024-13384Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.24 - Admin+ Stored XSSUnknown Photo Gallery, Images, Slider in Rbs Image Gallery
CVE-2024-11359Library Bookshelves <= 5.8 - Reflected Cross-Site Scriptingphotonicgnostic Library Bookshelves
CVE-2024-10545NextGEN Gallery < 3.59.9 - Admin+ Stored XSSUnknown Photo Gallery, Sliders, Proofing and Themes
CVE-2024-10144Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.22 - Contributor+ Stored XSSUnknown Photo Gallery, Images, Slider in Rbs Image Gallery
CVE-2024-10102Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.22 - Contributor+ Stored XSSUnknown Photo Gallery, Images, Slider in Rbs Image Gallery
CVE-2023-5307Photos and Files Contest Gallery – Contact Form < 21.2.8.1 - Unauthenticated Stored XSS via HTTP HeadersUnknown Photos and Files Contest Gallery
CVE-2023-47522WordPress Photo Feed Plugin <= 2.2.1 is vulnerable to Cross Site Scripting (XSS)Photo Feed
CVE-2023-39917WordPress Photo Gallery by Ays Plugin <= 5.2.6 is vulnerable to Cross Site Request Forgery (CSRF)Photo Gallery by Ays – Responsive Image Gallery
CVE-2023-3499Robo Gallery < 3.2.16 - Admin+ Stored XSSUnknown Photo Gallery, Images, Slider in Rbs Image Gallery
CVE-2023-33995WordPress Photo Gallery by 10Web plugin <= 1.8.15 - Broken Access Control vulnerabilityPhoto Gallery by 10Web
CVE-2023-32107WordPress Photo Gallery by Ays Plugin <= 5.1.3 is vulnerable to Cross Site Scripting (XSS)Photo Gallery by Ays – Responsive Image Gallery
CVE-2023-3092SMTP Mail <= 1.3.46 - Unauthenticated Stored Cross-Site Scripting via Email Subjectphotoboxone SMTP Mail
CVE-2023-24382WordPress Material Design Icons for Page Builders Plugin <= 1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)Photon WP Material Design Icons for Page Builders
CVE-2023-24374WordPress Material Design Icons for Page Builders Plugin <= 1.4.2 is vulnerable to Cross Site Scripting (XSS)Photon WP Material Design Icons for Page Builders
CVE-2022-1394Photo Gallery < 1.6.4 - Admin+ Stored Cross-Site ScriptingUnknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2022-1282Photo Gallery < 1.6.3 - Reflected Cross-Site ScriptingUnknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2022-1281Photo Gallery < 1.6.3 - Unauthenticated SQL InjectionUnknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2022-0169Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL InjectionUnknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2021-25041Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)Unknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2021-24363Photo Gallery < 1.5.75 - File Upload Path TraversalUnknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2021-24362Photo Gallery < 1.5.75 - Stored Cross-Site Scripting via Uploaded SVGUnknown Photo Gallery by 10Web – Mobile-Friendly Image…
CVE-2021-24291Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)Photo Gallery by 10Web – Mobile-Friendly Image Gallery
CVE-2021-24139Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL InjectionUnknown Photo Gallery by 10Web
CVE-2012-10051Photodex ProShow Producer 5.0.3256 load File Handling Buffer OverflowPhotodex Corporation ProShow Producer
59 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.