Imagely kayıtları
imagely üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,7
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %29,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2019-14314Kavram kanıtı | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.imagely · nextgen gallery · CWE-89 | Kritik9,8 | — | %43,4 | 27 Ağu 2019 |
45Planlayın | CVE-2013-3684Kavram kanıtı | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadimagely · nextgen gallery · CWE-434 | Kritik9,8 | — | %19,2 | 11 Şub 2020 |
40Planlayın | CVE-2016-10889İstismar yok | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.imagely · nextgen gallery · CWE-89 | Kritik9,8 | — | %1,8 | 14 Ağu 2019 |
36İzleyin | CVE-2015-9228İstismar yok | In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,imagely · nextgen gallery · CWE-434 | Yüksek8,8 | — | %3,7 | 12 Eyl 2017 |
36İzleyin | CVE-2015-1784İstismar yok | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weimagely · nextgen gallery · CWE-434 | Yüksek8,8 | — | %2,0 | 7 Tem 2022 |
35İzleyin | CVE-2013-0291Kavram kanıtı | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerabilityimagely · nextgen gallery · CWE-200 | Yüksek7,5 | — | %15,6 | 30 Oca 2020 |
35İzleyin | CVE-2020-35942İstismar yok | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusiimagely · nextgen gallery · CWE-79 | Yüksek8,8 | — | %1,4 | 9 Şub 2021 |
35İzleyin | CVE-2023-48328İstismar yok | WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)imagely · nextgen gallery · CWE-352 | Yüksek8,8 | — | %0,3 | 30 Kas 2023 |
32İzleyin | CVE-2024-3097Kavram kanıtı | WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosureimagely · nextgen gallery · CWE-862 | Orta5,3 | — | %38,0 | 9 Nis 2024 |
31İzleyin | CVE-2016-6565İstismar yok | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious fileimagely · nextgen gallery · CWE-98 | Yüksek7,5 | — | %2,5 | 13 Tem 2018 |
31İzleyin | CVE-2018-7586İstismar yok | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.imagely · nextgen gallery · CWE-22 | Yüksek7,5 | — | %2,0 | 1 Mar 2018 |
30İzleyin | CVE-2023-3154İstismar yok | NextGEN Gallery < 3.39 - Admin+ PHAR Deserializationimagely · nextgen gallery · CWE-502 | Yüksek7,5 | — | %0,7 | 16 Eki 2023 |
29İzleyin | CVE-2015-9538Silahlaştırılmış | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.imagely · nextgen gallery · CWE-22 | Orta6,5 | — | %10,1 | 26 Kas 2019 |
28İzleyin | CVE-2023-3155İstismar yok | NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Deleteimagely · nextgen gallery · CWE-552 | Yüksek7,2 | — | %0,8 | 16 Eki 2023 |
26İzleyin | CVE-2020-35943İstismar yok | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.imagely · nextgen gallery · CWE-352 | Orta6,5 | — | %0,7 | 9 Şub 2021 |
26İzleyin | CVE-2015-1785İstismar yok | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weimagely · nextgen gallery · CWE-434 | Orta6,5 | — | %0,7 | 7 Tem 2022 |
24İzleyin | CVE-2021-24293İstismar yok | NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)imagely · nextgen gallery · CWE-79 | Orta6,1 | — | %0,9 | 5 May 2021 |
23İzleyin | CVE-2024-5442İstismar yok | NextGEN Gallery < 3.59.3 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Orta5,9 | — | %0,4 | 13 Tem 2024 |
21İzleyin | CVE-2015-9537İstismar yok | The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumimagely · nextgen gallery · CWE-79 | Orta5,4 | — | %1,2 | 26 Kas 2019 |
19İzleyin | CVE-2015-9229İstismar yok | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticatedimagely · nextgen gallery · CWE-79 | Orta4,8 | — | %1,0 | 12 Eyl 2017 |
19İzleyin | CVE-2023-3279İstismar yok | NextGEN Gallery < 3.39 - Admin+ Local File Inclusionimagely · nextgen gallery · CWE-22 | Orta4,9 | — | %0,8 | 16 Eki 2023 |
19İzleyin | CVE-2018-1000172İstismar yok | Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.imagely · nextgen gallery · CWE-79 | Orta4,8 | — | %0,6 | 30 Nis 2018 |
19İzleyin | CVE-2024-6393İstismar yok | NextGEN Gallery < 3.59.5 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Orta4,8 | — | %0,5 | 25 Kas 2024 |
19İzleyin | CVE-2024-39627İstismar yok | WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerabilityimagely · nextgen gallery · CWE-79 | Orta4,8 | — | %0,3 | 1 Ağu 2024 |
17İzleyin | CVE-2024-2744İstismar yok | Nextgen Gallery < 3.59.1 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Orta4,3 | — | %0,4 | 17 May 2024 |
- CVE-2019-1431452Planlayın
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.
KritikCVSS 9,8Kavram kanıtıEPSS %43imagely · nextgen gallery27 Ağu 2019
- CVE-2013-368445Planlayın
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
KritikCVSS 9,8Kavram kanıtıEPSS %19imagely · nextgen gallery11 Şub 2020
- CVE-2016-1088940Planlayın
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
KritikCVSS 9,8İstismar yokEPSS %2imagely · nextgen gallery14 Ağu 2019
- CVE-2015-922836İzleyin
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,
YüksekCVSS 8,8İstismar yokEPSS %4imagely · nextgen gallery12 Eyl 2017
- CVE-2015-178436İzleyin
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we
YüksekCVSS 8,8İstismar yokEPSS %2imagely · nextgen gallery7 Tem 2022
- CVE-2013-029135İzleyin
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
YüksekCVSS 7,5Kavram kanıtıEPSS %16imagely · nextgen gallery30 Oca 2020
- CVE-2020-3594235İzleyin
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusi
YüksekCVSS 8,8İstismar yokEPSS %1imagely · nextgen gallery9 Şub 2021
- CVE-2023-4832835İzleyin
WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0imagely · nextgen gallery30 Kas 2023
- CVE-2024-309732İzleyin
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
OrtaCVSS 5,3Kavram kanıtıEPSS %38imagely · nextgen gallery9 Nis 2024
- CVE-2016-656531İzleyin
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file
YüksekCVSS 7,5İstismar yokEPSS %3imagely · nextgen gallery13 Tem 2018
- CVE-2018-758631İzleyin
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
YüksekCVSS 7,5İstismar yokEPSS %2imagely · nextgen gallery1 Mar 2018
- CVE-2023-315430İzleyin
NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization
YüksekCVSS 7,5İstismar yokEPSS %1imagely · nextgen gallery16 Eki 2023
- CVE-2015-953829İzleyin
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
OrtaCVSS 6,5SilahlaştırılmışEPSS %10imagely · nextgen gallery26 Kas 2019
- CVE-2023-315528İzleyin
NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete
YüksekCVSS 7,2İstismar yokEPSS %1imagely · nextgen gallery16 Eki 2023
- CVE-2020-3594326İzleyin
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.
OrtaCVSS 6,5İstismar yokEPSS %1imagely · nextgen gallery9 Şub 2021
- CVE-2015-178526İzleyin
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we
OrtaCVSS 6,5İstismar yokEPSS %1imagely · nextgen gallery7 Tem 2022
- CVE-2021-2429324İzleyin
NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %1imagely · nextgen gallery5 May 2021
- CVE-2024-544223İzleyin
NextGEN Gallery < 3.59.3 - Admin+ Stored XSS
OrtaCVSS 5,9İstismar yokEPSS %0imagely · nextgen gallery13 Tem 2024
- CVE-2015-953721İzleyin
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thum
OrtaCVSS 5,4İstismar yokEPSS %1imagely · nextgen gallery26 Kas 2019
- CVE-2015-922919İzleyin
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated
OrtaCVSS 4,8İstismar yokEPSS %1imagely · nextgen gallery12 Eyl 2017
- CVE-2023-327919İzleyin
NextGEN Gallery < 3.39 - Admin+ Local File Inclusion
OrtaCVSS 4,9İstismar yokEPSS %1imagely · nextgen gallery16 Eki 2023
- CVE-2018-100017219İzleyin
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.
OrtaCVSS 4,8İstismar yokEPSS %1imagely · nextgen gallery30 Nis 2018
- CVE-2024-639319İzleyin
NextGEN Gallery < 3.59.5 - Admin+ Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %0imagely · nextgen gallery25 Kas 2024
- CVE-2024-3962719İzleyin
WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 4,8İstismar yokEPSS %0imagely · nextgen gallery1 Ağu 2024
- CVE-2024-274417İzleyin
Nextgen Gallery < 3.59.1 - Admin+ Stored XSS
OrtaCVSS 4,3İstismar yokEPSS %0imagely · nextgen gallery17 May 2024