Tinywebgallery is a modestly represented vendor in the vulnerability landscape, with a focused portfolio centered on its namesake web gallery product alongside related web-facing components such as Advanced Iframe and WordPress Flash Uploader plugins. Vulnerabilities affecting the vendor's products cluster around web-application input handling and request validation, with recurring weakness classes including cross-site scripting, improper input validation, and cross-site request forgery that reflect the interactive, user-generated-content nature of gallery and media-upload functionality. A meaningful share of the vendor's disclosures reach serious severity, and public exploit code has an elevated tendency to become available for its vulnerabilities, making timely patching of exposed instances important for defenders. The exposure to these web-tier flaws underscores the importance of inventory and monitoring for this widely embedded gallery component. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinywebgallery over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5347HIGH TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php. | Oct 9, 2012 | 7.5 | 33 | NO | YES |
CVE-2014-5014CRITICAL The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path. | Apr 25, 2018 | 9.8 | 32 | NO | NO |
CVE-2006-4166HIGH PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or | Aug 16, 2006 | 7.5 | 29 | NO | YES |
CVE-2023-53922CRITICAL TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers | Dec 17, 2025 | 9.8 | 28 | NO | NO |
CVE-2009-1911MEDIUM Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remo | Jun 4, 2009 | 6.8 | 27 | NO | YES |
CVE-2021-24953MEDIUM The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Si | Mar 7, 2022 | 6.1 | 23 | NO | NO |
CVE-2012-2931HIGH PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file. | Jan 9, 2020 | 7.2 | 23 | NO | NO |
CVE-2012-2930MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests t | Apr 24, 2015 | 6.8 | 21 | NO | NO |
CVE-2006-1802MEDIUM Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter. | Apr 18, 2006 | 4.3 | 21 | NO | YES |
CVE-2023-53939MEDIUM TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attacker | Dec 18, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinywebgallery.
Media articles that mention a CVE ID that affects a product developed by Tinywebgallery — matched by CVE ID, not by vendor name.