Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
imagely nextgen gallery vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2020-35943
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin prior to 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Imagely Nextgen Gallery
356
VMScore
CVE-2015-9538
The NextGEN Gallery plugin prior to 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Imagely Nextgen Gallery
312
VMScore
CVE-2015-9537
The NextGEN Gallery plugin prior to 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
Imagely Nextgen Gallery
312
VMScore
CVE-2018-1000172
Imagely NextGEN Gallery version 2.2.30 and previous versions contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been ...
Imagely Nextgen Gallery
312
VMScore
CVE-2015-9229
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
Imagely Nextgen Gallery 2.1.15
NA
CVE-2024-3097
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated malicious users to ...
Imagely Nextgen Gallery
NA
CVE-2023-48328
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a up to and including 3.37.
Imagely Nextgen Gallery
NA
CVE-2023-3154
The WordPress Gallery Plugin WordPress plugin prior to 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an malicious user to access arbitrary resources on the server.
Imagely Nextgen Gallery
NA
CVE-2023-3279
The WordPress Gallery Plugin WordPress plugin prior to 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
Imagely Nextgen Gallery
NA
CVE-2023-3155
The WordPress Gallery Plugin WordPress plugin prior to 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an malicious user to access arbitrary resources on the server.
Imagely Nextgen Gallery
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »