Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1348▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.40%—Nextgen GalleryAI30/9/202630/9/2026
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
AplazadaAlta (7.1)0.47%—Nextgen GalleryAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
AplazadaCrítica (9.3)0.37%—Nextgen GalleryAI20/5/202623/7/2026
NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'. The root cause is an insufficient sanitization function ('_clean_column()') in the data mapper layer that uses a character…
AplazadaMedia (4.3)0.26%—Nextgen GalleryAI20/5/202624/7/2026
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE…
AplazadaAlta (8.8)0.45%—Nextgen GalleryAI18/3/202617/6/2026
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include…
AplazadaAlta (8.8)0.75%—Photogallery Nextgen GalleryAI18/12/202517/6/2026
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.59.12 via the 'template' shortcode parameter. This is due to insufficient path validation that allows absolute paths to be provided. This makes it…
AplazadaAlta (7.1)0.23%—Koen Schuit Nextgen Gallery SearchAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Koen Schuit NextGEN Gallery Search nextgen-gallery-search-galleries allows Reflected XSS.This issue affects NextGEN Gallery Search: from n/a through <= 2.12.
AplazadaAlta (7.1)0.31%—Shauno Nextgen-gallery-votingAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shauno NextGEN Gallery Voting nextgen-gallery-voting allows Reflected XSS.This issue affects NextGEN Gallery Voting: from n/a through <= 2.7.6.
AnalizadaBaja (3.5)0.35%—Imagely Nextgen Gallery25/2/202517/6/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (4.8)0.47%—Imagely Nextgen Gallery25/11/202417/6/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (4.8)0.32%—Imagely Nextgen Gallery1/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Gallery allows Stored XSS.This issue affects NextGEN Gallery: from n/a through 3.59.3.
AnalizadaMedia (5.9)0.38%—Imagely Nextgen Gallery13/7/202417/6/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (4.3)0.39%—Imagely Nextgen Gallery17/5/202417/6/2026
The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (5.3)38%—Imagely Nextgen Gallery9/4/202417/6/2026
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other…
ModificadaAlta (8.8)0.27%—Imagely Nextgen Gallery30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
ModificadaMedia (4.9)0.79%—Imagely Nextgen Gallery16/10/202317/6/2026
The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
ModificadaAlta (7.2)0.81%—Imagely Nextgen Gallery16/10/202317/6/2026
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
ModificadaAlta (7.5)0.70%—Imagely Nextgen Gallery16/10/202317/6/2026
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
ModificadaMedia (6.5)0.22%—Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
ModificadaMedia (6.1)0.39%—Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview20/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
ModificadaMedia (4.3)0.23%—Imagely Nextgen Gallery1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
ModificadaMedia (6.5)0.70%—Imagely Nextgen Gallery7/7/202217/6/2026
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
ModificadaAlta (8.8)2.0%—Imagely Nextgen Gallery7/7/202217/6/2026
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
ModificadaMedia (6.1)0.87%—Imagely Nextgen Gallery5/5/202117/6/2026
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
ModificadaMedia (6.5)0.73%—Imagely Nextgen Gallery9/2/202117/6/2026
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)