The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An attacker must target an authenticated user with permissions to access this feature, however once uploaded the payload is also accessible to unauthenticated users.
We have discovered 26,786 live websites that are affected by CVE-2024-29833.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 26,786 live websites (30% of Photo Gallery by 10Web install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 331 versions ( 54% of all versions) |
| 4,612 websites | |
| 2,990 websites | |
| 1,899 websites | |
| 1,600 websites | |
| 1,459 websites | |
| 1,445 websites | |
| 1,093 websites | |
| 826 websites | |
| 791 websites | |
| 710 websites |
| .com | 8,592 websites |
| .de | 1,734 websites |
| .ru | 1,285 websites |
| .it | 1,281 websites |
| .org | 1,270 websites |
| .pl | 1,107 websites |
| .cz | 714 websites |
| .nl | 672 websites |
| .co.uk | 592 websites |
| .net | 577 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.name | **,*** | ||
| **********.**.uk | **,*** | ||
| ********.cz | **,*** | ||
| ************.net | **,*** | ||
| ***.org | **,*** | ||
| ******************.org | **,*** | ||
| *****.edu | ***,*** | ||
| ***************.com | ***,*** | ||
| ******.com | ***,*** | ||
| ***************.it | ***,*** |
FAQ