Imagely Nextgen Gallery vulnerabilities
27 known vulnerabilities affecting imagely/nextgen_gallery.
Total CVEs
27
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM14LOW1
Vulnerabilities
Page 2 of 2
CVE-2019-14314CRITICALCVSS 9.8fixed in 3.2.102019-08-27
CVE-2019-14314 [CRITICAL] CWE-89 CVE-2019-14314: A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPre
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
nvd
CVE-2016-10889CRITICALCVSS 9.8fixed in 2.1.572019-08-14
CVE-2016-10889 [CRITICAL] CWE-89 CVE-2016-10889: The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
nvd
CVE-2016-6565HIGHCVSS 7.5fixed in 2.1.572018-07-13
CVE-2016-6565 [HIGH] CWE-98 CVE-2016-6565: The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).
nvd
CVE-2018-1000172MEDIUMCVSS 4.8≤ 2.2.302018-04-30
CVE-2018-1000172 [MEDIUM] CWE-79 CVE-2018-1000172: Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerabili
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.
nvd
CVE-2018-7586HIGHCVSS 7.5≤ 2.2.462018-03-01
CVE-2018-7586 [HIGH] CWE-22 CVE-2018-7586: In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
nvd
CVE-2015-9228HIGHCVSS 8.8v1.5.0v1.5.1+68 more2017-09-12
CVE-2015-9228 [HIGH] CWE-434 CVE-2015-9228: In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upl
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
nvd
CVE-2015-9229MEDIUMCVSS 4.8v2.1.152017-09-12
CVE-2015-9229 [MEDIUM] CWE-79 CVE-2015-9229: In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress,
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
nvd
← Previous2 / 2