Total
27 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-7586 | 1 Imagely | 1 Nextgen Gallery | 2020-03-05 | 5.0 MEDIUM | 7.5 HIGH |
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. | |||||
CVE-2013-3684 | 1 Imagely | 1 Nextgen Gallery | 2020-02-13 | 10.0 HIGH | 9.8 CRITICAL |
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | |||||
CVE-2013-0291 | 1 Imagely | 1 Nextgen Gallery | 2020-02-06 | 5.0 MEDIUM | 7.5 HIGH |
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability | |||||
CVE-2019-14314 | 1 Imagely | 1 Nextgen Gallery | 2019-12-16 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php. | |||||
CVE-2016-6565 | 1 Imagely | 1 Nextgen Gallery | 2019-10-09 | 6.0 MEDIUM | 7.5 HIGH |
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration). | |||||
CVE-2016-10889 | 1 Imagely | 1 Nextgen Gallery | 2019-08-16 | 7.5 HIGH | 9.8 CRITICAL |
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | |||||
CVE-2018-1000172 | 1 Imagely | 1 Nextgen Gallery | 2018-06-07 | 3.5 LOW | 4.8 MEDIUM |
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45. |