Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nextgen gallery vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2020-35942
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin prior to 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including ...
Imagely Nextgen Gallery
8.8
CVSSv3
CVE-2015-1784
In nextgen-galery wordpress plugin prior to 2.0.77.3 there are two vulnerabilities which can allow an malicious user to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing...
Imagely Nextgen Gallery
6.5
CVSSv3
CVE-2015-1785
In nextgen-galery wordpress plugin prior to 2.0.77.3 there are two vulnerabilities which can allow an malicious user to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing...
Imagely Nextgen Gallery
6.5
CVSSv3
CVE-2020-35943
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin prior to 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Imagely Nextgen Gallery
9.8
CVSSv3
CVE-2019-14314
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin prior to 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote malicious user to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display...
Imagely Nextgen Gallery
1 Github repository
4.3
CVSSv3
CVE-2022-38468
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
Imagely Nextgen Gallery
4.8
CVSSv3
CVE-2018-1000172
Imagely NextGEN Gallery version 2.2.30 and previous versions contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been ...
Imagely Nextgen Gallery
9.8
CVSSv3
CVE-2016-10889
The nextgen-gallery plugin prior to 2.1.57 for WordPress has SQL injection via a gallery name.
Imagely Nextgen Gallery
5.4
CVSSv3
CVE-2015-9537
The NextGEN Gallery plugin prior to 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
Imagely Nextgen Gallery
9.8
CVSSv3
CVE-2013-3684
NextGEN Gallery plugin prior to 1.9.13 for WordPress: ngggallery.php file upload
Imagely Nextgen Gallery
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »