Cross-site Scripting Vulnerability in 10Web Photo Gallery by 10Web
CVE-2026-27360

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 February 2026

What is CVE-2026-27360?

The 10Web Photo Gallery is vulnerable to an improper neutralization of input during web page generation, specifically allowing for Stored Cross-site Scripting (XSS) attacks. This vulnerability can potentially allow attackers to inject malicious scripts into pages viewed by users, impairing the security and integrity of the site. Affected versions of the Photo Gallery include all prior to 1.8.37. Website administrators are urged to evaluate their installations and apply necessary updates or patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Photo Gallery by 10Web <= n/a

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tabulra | Patchstack Bug Bounty Program
.