Imagely
Imagely Nextgen Gallery: vulnerabilidades y CVE
Imagely Nextgen Gallery tiene 27 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-10545 | Baja (3.5) | 0.35% | — | 25 feb 2025 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site… |
| CVE-2024-6393 | Media (4.8) | 0.47% | — | 25 nov 2024 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege users such as Admin to perform Stored Cross-Site… |
| CVE-2024-39627 | Media (4.8) | 0.32% | — | 1 ago 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Gallery allows Stored XSS.This issue affects NextGEN Gallery: from n/a through 3.59.3. |
| CVE-2024-5442 | Media (5.9) | 0.38% | — | 13 jul 2024 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting… |
| CVE-2024-2744 | Media (4.3) | 0.39% | — | 17 may 2024 | The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when… |
| CVE-2024-3097 | Media (5.3) | 38% | — | 9 abr 2024 | The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This… |
| CVE-2023-48328 | Alta (8.8) | 0.27% | — | 30 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through… |
| CVE-2023-3279 | Media (4.9) | 0.79% | — | 16 oct 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks |
| CVE-2023-3155 | Alta (7.2) | 0.81% | — | 16 oct 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access… |
| CVE-2023-3154 | Alta (7.5) | 0.70% | — | 16 oct 2023 | The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary… |
| CVE-2022-38468 | Media (4.3) | 0.23% | — | 1 mar 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration. |
| CVE-2015-1785 | Media (6.5) | 0.70% | — | 7 jul 2022 | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user… |
| CVE-2015-1784 | Alta (8.8) | 2.0% | — | 7 jul 2022 | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user… |
| CVE-2021-24293 | Media (6.1) | 0.87% | — | 5 may 2021 | In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject… |
| CVE-2020-35943 | Media (6.5) | 0.73% | — | 9 feb 2021 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.) |
| CVE-2020-35942 | Alta (8.8) | 1.4% | — | 9 feb 2021 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is… |
| CVE-2013-3684 | Crítica (9.8) | 19% | — | 11 feb 2020 | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload |
| CVE-2013-0291 | Alta (7.5) | 16% | — | 30 ene 2020 | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability |
| CVE-2015-9538 | Media (6.5) | 10% | — | 26 nov 2019 | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. |
| CVE-2015-9537 | Media (5.4) | 1.2% | — | 26 nov 2019 | The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template. |
| CVE-2019-14314 | Crítica (9.8) | 43% | — | 27 ago 2019 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on… |
| CVE-2016-10889 | Crítica (9.8) | 1.8% | — | 14 ago 2019 | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. |
| CVE-2016-6565 | Alta (7.5) | 2.5% | — | 13 jul 2018 | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary… |
| CVE-2018-1000172 | Media (4.8) | 0.57% | — | 30 abr 2018 | Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator… |
| CVE-2018-7586 | Alta (7.5) | 2.0% | — | 1 mar 2018 | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. |
| CVE-2015-9229 | Media (4.8) | 0.99% | — | 12 sept 2017 | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter. |
| CVE-2015-9228 | Alta (8.8) | 3.7% | — | 12 sept 2017 | In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php. |