The Simple Image Gallery Web App Project maintains a single, narrowly scoped web application where vulnerabilities center on input handling and file management. Its recurring weakness classes—including injection flaws, SQL injection, and unrestricted file uploads—are characteristic of web applications that process user-supplied content without sufficient validation and sanitization.
The number and severity of CVEs published that impact products developed by Simple Image Gallery Web App Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27040CRITICAL Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. | Mar 16, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-38753CRITICAL An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app. | Aug 16, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-38819HIGH A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page. | Nov 17, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Image Gallery Web App Project.
Media articles that mention a CVE ID that affects a product developed by Simple Image Gallery Web App Project — matched by CVE ID, not by vendor name.