# Exploit Title: TinyWebGallery 2.7 - Authenticated Stored XSS # Date: 2025-27-06 # Exploit Author: tmrswrr # Vendor Homepage: https://www.tinywebgallery.com # Version: 2.7 # Tested on: https://www.tinywebgallery.com/en/download.php 1 ) Log in as admin and GO > https://127.0.0.1/TinyWebGallery/admin/index.php 2 ) TWG album description left write payload : "> 3 ) Click Create , you will be see alert button