Product
imagely nextgen gallery
29 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-10545
CVE-2024-6393
CVE-2024-39627
CVE-2024-5442
CVE-2024-2744
CVE-2024-3097
CVE-2023-48328
CVE-2023-3279
CVE-2023-3155
CVE-2023-3154
CVE-2022-38468
CVE-2015-1785
CVE-2015-1784
CVE-2021-24293
CVE-2020-35943
CVE-2020-35942
CVE-2013-3684
CVE-2013-0291
CVE-2015-9538
CVE-2015-9537
CVE-2019-14314
CVE-2016-10889
CVE-2016-6565
CVE-2018-1000172
CVE-2018-7586
CVE-2015-9229
CVE-2015-9228
CVE-2010-1186
CVE-2008-7175
< 3.59.9
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings,
< 3.59.5
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings
< 3.59.4
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Galle
< 3.59.3
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which
< 3.59.1
The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high priv
< 3.59.1
The WordPress Gallery Plugin - NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing
< 3.39
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin - NextGEN Gallery allows Cross Site Request Fo
< 3.39
The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate pa
< 3.39
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input p
< 3.39
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter v
< 3.29
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin - NextGEN Gallery plugin <= 3.28 leading to t
< 2.0.77.3
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access o
< 2.0.77.3
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access o
< 3.1.11
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via p
< 3.5.0
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is poss
< 3.5.0
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local Fi
< 1.9.13
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
all versions
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
< 2.1.15
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
< 2.1.10
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbw
< 3.2.10
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of
< 2.1.57
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
< 2.1.57
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile para
<= 2.2.30
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.
<= 2.2.46
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
all versions
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote aut
all versions
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name
<= 1.5.1
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remo
<= 0.96
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows rem