TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.
References
| Link | Resource |
|---|---|
| http://www.tinywebgallery.com/ | Product |
| https://www.exploit-db.com/exploits/51442 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/tinywebgallery-stored-cross-site-scripting-via-folder-name-parameter | Third Party Advisory |
| https://www.exploit-db.com/exploits/51442 | Exploit Third Party Advisory VDB Entry |
Configurations
History
24 Dec 2025, 16:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.tinywebgallery.com/ - Product | |
| References | () https://www.exploit-db.com/exploits/51442 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/tinywebgallery-stored-cross-site-scripting-via-folder-name-parameter - Third Party Advisory | |
| First Time |
Tinywebgallery tinywebgallery
Tinywebgallery |
|
| CPE | cpe:2.3:a:tinywebgallery:tinywebgallery:2.5:*:*:*:*:*:*:* |
18 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/51442 - |
18 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 20:15
Updated : 2025-12-24 16:46
NVD link : CVE-2023-53939
Mitre link : CVE-2023-53939
CVE.ORG link : CVE-2023-53939
JSON object : View
Products Affected
tinywebgallery
- tinywebgallery
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
