An SQLi I found in Photo Gallery by 10Web was disclosed this week!
cryptocat.me/blog/researc...
Root cause analysis of CVE-2026-9829 in Photo Gallery by 10Web, where compact album shortcode sort direction was stored then later reached an album ORDER BY clause and allowed Contributor+ time-based ...