Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
imagely nextgen gallery vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2024-3097
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated malicious users to ...
Imagely Nextgen Gallery
8.8
CVSSv3
CVE-2023-48328
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a up to and including 3.37.
Imagely Nextgen Gallery
7.5
CVSSv3
CVE-2023-3154
The WordPress Gallery Plugin WordPress plugin prior to 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an malicious user to access arbitrary resources on the server.
Imagely Nextgen Gallery
7.2
CVSSv3
CVE-2023-3155
The WordPress Gallery Plugin WordPress plugin prior to 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an malicious user to access arbitrary resources on the server.
Imagely Nextgen Gallery
4.9
CVSSv3
CVE-2023-3279
The WordPress Gallery Plugin WordPress plugin prior to 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
Imagely Nextgen Gallery
4.3
CVSSv3
CVE-2022-38468
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
Imagely Nextgen Gallery
6.5
CVSSv3
CVE-2015-1785
In nextgen-galery wordpress plugin prior to 2.0.77.3 there are two vulnerabilities which can allow an malicious user to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing...
Imagely Nextgen Gallery
8.8
CVSSv3
CVE-2015-1784
In nextgen-galery wordpress plugin prior to 2.0.77.3 there are two vulnerabilities which can allow an malicious user to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing...
Imagely Nextgen Gallery
8.8
CVSSv3
CVE-2020-35942
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin prior to 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including ...
Imagely Nextgen Gallery
6.5
CVSSv3
CVE-2020-35943
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin prior to 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Imagely Nextgen Gallery
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »