Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tinywebgallery

First CVE: Apr 18, 2006Active for: 20 yearsTotal CVEs: 23
28.9
VTI Score
Low

Tinywebgallery is a modestly represented vendor in the vulnerability landscape, with a focused portfolio centered on its namesake web gallery product alongside related web-facing components such as Advanced Iframe and WordPress Flash Uploader plugins. Vulnerabilities affecting the vendor's products cluster around web-application input handling and request validation, with recurring weakness classes including cross-site scripting, improper input validation, and cross-site request forgery that reflect the interactive, user-generated-content nature of gallery and media-upload functionality. A meaningful share of the vendor's disclosures reach serious severity, and public exploit code has an elevated tendency to become available for its vulnerabilities, making timely patching of exposed instances important for defenders. The exposure to these web-tier flaws underscores the importance of inventory and monitoring for this widely embedded gallery component. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tinywebgallery over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2006
20 years ago
Most Recent CVE
Dec 18, 2025
218 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-5347HIGH
TinyWebGallery 1.8.3 allows remote attackers to execute arbitrary code via shell metacharacters in the command parameter to (1) inc/filefunctions.inc or (2) info.php.
Oct 9, 20127.533NOYES
CVE-2014-5014CRITICAL
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
Apr 25, 20189.832NONO
CVE-2006-4166HIGH
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or
Aug 16, 20067.529NOYES
CVE-2023-53922CRITICAL
TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers
Dec 17, 20259.828NONO
CVE-2009-1911MEDIUM
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remo
Jun 4, 20096.827NOYES
CVE-2021-24953MEDIUM
The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Si
Mar 7, 20226.123NONO
CVE-2012-2931HIGH
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
Jan 9, 20207.223NONO
CVE-2012-2930MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests t
Apr 24, 20156.821NONO
CVE-2006-1802MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.
Apr 18, 20064.321NOYES
CVE-2023-53939MEDIUM
TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attacker
Dec 18, 20255.419NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
78%
13%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (65.2%)
Unknown8 (34.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (65.2%)
High0 (0.0%)
Unknown8 (34.8%)
User Interaction
None5 (21.7%)
Unknown8 (34.8%)
Required10 (43.5%)
Privileges Required
Low9 (39.1%)
High1 (4.3%)
None5 (21.7%)
Unknown8 (34.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
17.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tinywebgallery.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tinywebgallery — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tinywebgallery's Products

View all 5 CNAs →

Top CWEs