VendorsImagelynextgen_galleryany version
Vulnerabilities

Imagely NextGEN Gallery any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2013-3684
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Published 2020-02-11 · Modified
10.01 PoCEPSS 0.192
CVE-2019-14314
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
Published 2019-08-27 · Modified
9.8EPSS 0.434
CVE-2016-10889
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
Published 2019-08-14 · Modified
9.8EPSS 0.018
CVE-2015-1784
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Published 2022-07-07 · Modified
8.8EPSS 0.020
CVE-2020-35942
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Published 2021-02-09 · Modified
8.8EPSS 0.014
CVE-2023-48328
WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-30 · Modified
8.8EPSS 0.003
CVE-2016-6565
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file
Published 2018-07-13 · Modified
7.5EPSS 0.025
CVE-2018-7586
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
Published 2018-03-01 · Modified
7.5EPSS 0.020
CVE-2023-3154
NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization
Published 2023-10-16 · Modified
7.5EPSS 0.007
CVE-2023-3155
NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete
Published 2023-10-16 · Modified
7.2EPSS 0.008
CVE-2015-9538
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Published 2019-11-26 · Modified
6.5EPSS 0.101
CVE-2020-35943
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Published 2021-02-09 · Modified
6.5EPSS 0.007
CVE-2015-1785
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Published 2022-07-07 · Modified
6.5EPSS 0.007
CVE-2021-24293
NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
Published 2021-05-05 · Modified
6.1EPSS 0.009
CVE-2024-5442
NextGEN Gallery < 3.59.3 - Admin+ Stored XSS
Published 2024-07-13 · Analyzed
5.9EPSS 0.004
CVE-2024-39627
WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability
Published 2024-08-01 · Analyzed
5.9EPSS 0.003
CVE-2015-9537
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
Published 2019-11-26 · Modified
5.4EPSS 0.012
CVE-2024-3097
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
Published 2024-04-09 · Modified
5.3EPSS 0.380
CVE-2023-3279
NextGEN Gallery < 3.39 - Admin+ Local File Inclusion
Published 2023-10-16 · Modified
4.9EPSS 0.008
CVE-2018-1000172
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.
Published 2018-04-30 · Modified
4.8EPSS 0.006
CVE-2024-6393
NextGEN Gallery < 3.59.5 - Admin+ Stored XSS
Published 2024-11-25 · Analyzed
4.8EPSS 0.005
CVE-2024-2744
Nextgen Gallery < 3.59.1 - Admin+ Stored XSS
Published 2024-05-17 · Analyzed
4.3EPSS 0.004
CVE-2022-38468
WordPress NextGEN Gallery Plugin <= 3.28 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-03-01 · Modified
4.3EPSS 0.002
CVE-2024-10545
NextGEN Gallery < 3.59.9 - Admin+ Stored XSS
Published 2025-02-25 · Analyzed
3.5EPSS 0.003