← Back

Imagely

imagely

27 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Imagely
1Nextgen Gallery
Nov 21, 2024
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the...Show more
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.Show less
1Imagely
1Nextgen Gallery
Nov 21, 2024
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
1Imagely
1Nextgen Gallery
Nov 21, 2024
Jul 13, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary file...Show more
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).Show less
1Imagely
1Nextgen Gallery
Nov 21, 2024
Apr 30, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator...Show more
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.Show less
1Imagely
1Nextgen Gallery
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
1Imagely
1Nextgen Gallery
May 13, 2026
Sep 12, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
1Imagely
1Nextgen Gallery
May 13, 2026
Sep 12, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.