Imagely / Nextgen Gallery
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-10545 | NextGEN Gallery < 3.59.9 - Admin+ Stored XSS | LOW | 3.5 | Feb 25, 2025 |
| CVE-2024-6393 | NextGEN Gallery < 3.59.5 - Admin+ Stored XSS | MEDIUM | 4.8 | Nov 25, 2024 |
| CVE-2024-39627 | WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 5.9 | Aug 1, 2024 |
| CVE-2024-5442 | NextGEN Gallery < 3.59.3 - Admin+ Stored XSS | MEDIUM | 5.9 | Jul 13, 2024 |
| CVE-2024-2744 | Nextgen Gallery < 3.59.1 - Admin+ Stored XSS | MEDIUM | 4.3 | May 17, 2024 |
| CVE-2024-3097 | WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure | MEDIUM | 5.3 | Apr 9, 2024 |
| CVE-2023-48328 | WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF) | HIGH | 8.8 | Nov 30, 2023 |
| CVE-2023-3279 | NextGEN Gallery < 3.39 - Admin+ Local File Inclusion | MEDIUM | 4.9 | Oct 16, 2023 |
| CVE-2023-3155 | NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete | HIGH | 7.2 | Oct 16, 2023 |
| CVE-2023-3154 | NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization | HIGH | 7.5 | Oct 16, 2023 |
| CVE-2022-38468 | WordPress NextGEN Gallery Plugin <= 3.28 is vulnerable to Cross Site Request Forgery (CSRF) | MEDIUM | 4.3 | Mar 1, 2023 |
| CVE-2015-1784 | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The… | HIGH | 8.8 | Jul 7, 2022 |
| CVE-2015-1785 | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The… | MEDIUM | 6.5 | Jul 7, 2022 |
| CVE-2021-24293 | NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS) | MEDIUM | 6.1 | May 5, 2021 |
| CVE-2020-35943 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protectio… | MEDIUM | 6.5 | Feb 9, 2021 |
| CVE-2020-35942 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings mod… | HIGH | 8.8 | Feb 9, 2021 |
| CVE-2013-3684 | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | CRITICAL | 9.8 | Feb 11, 2020 |
| CVE-2013-0291 | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability | HIGH | 7.5 | Jan 30, 2020 |
| CVE-2015-9537 | The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, an… | MEDIUM | 5.4 | Nov 26, 2019 |
| CVE-2015-9538 | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. | MEDIUM | 6.5 | Nov 26, 2019 |
| CVE-2019-14314 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would all… | CRITICAL | 9.8 | Aug 27, 2019 |
| CVE-2016-10889 | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | CRITICAL | 9.8 | Aug 14, 2019 |
| CVE-2016-6565 | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file | HIGH | 7.5 | Jul 13, 2018 |
| CVE-2018-1000172 | Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exp… | MEDIUM | 4.8 | Apr 30, 2018 |
| CVE-2018-7586 | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. | HIGH | 7.5 | Mar 1, 2018 |
Showing 1 to 25 of 27 CVEs