CVE-2026-49771
HIGHWordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability
Title source: cnaDescription
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
References (1)
Core 1
Scores
CVSS v3
7.6
EPSS
0.0023
EPSS Percentile
13.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (1)
10Web/Photo Gallery by 10Web
< 1.8.41
Published
Jun 04, 2026
Tracked Since
Jun 04, 2026