Skip to content
Noroxi

Imagely records

27 published records for vendor imagely.

All records

27 records
  • A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.

    CriticalCVSS 9.8Proof of conceptEPSS 43%

    imagely · nextgen galleryAug 27, 2019

  • NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    imagely · nextgen galleryFeb 11, 2020

  • The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.

    CriticalCVSS 9.8No exploitEPSS 2%

    imagely · nextgen galleryAug 14, 2019

  • CVE-2015-9228
    36Monitor

    In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,

    HighCVSS 8.8No exploitEPSS 4%

    imagely · nextgen gallerySep 12, 2017

  • CVE-2015-1784
    36Monitor

    In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we

    HighCVSS 8.8No exploitEPSS 2%

    imagely · nextgen galleryJul 7, 2022

  • CVE-2013-0291
    35Monitor

    NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability

    HighCVSS 7.5Proof of conceptEPSS 16%

    imagely · nextgen galleryJan 30, 2020

  • A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusi

    HighCVSS 8.8No exploitEPSS 1%

    imagely · nextgen galleryFeb 9, 2021

  • WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    imagely · nextgen galleryNov 30, 2023

  • CVE-2024-3097
    32Monitor

    WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure

    MediumCVSS 5.3Proof of conceptEPSS 38%

    imagely · nextgen galleryApr 9, 2024

  • CVE-2016-6565
    31Monitor

    The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file

    HighCVSS 7.5No exploitEPSS 3%

    imagely · nextgen galleryJul 13, 2018

  • CVE-2018-7586
    31Monitor

    In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.

    HighCVSS 7.5No exploitEPSS 2%

    imagely · nextgen galleryMar 1, 2018

  • CVE-2023-3154
    30Monitor

    NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization

    HighCVSS 7.5No exploitEPSS 1%

    imagely · nextgen galleryOct 16, 2023

  • CVE-2015-9538
    29Monitor

    The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

    MediumCVSS 6.5WeaponizedEPSS 10%

    imagely · nextgen galleryNov 26, 2019

  • CVE-2023-3155
    28Monitor

    NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete

    HighCVSS 7.2No exploitEPSS 1%

    imagely · nextgen galleryOct 16, 2023

  • A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.

    MediumCVSS 6.5No exploitEPSS 1%

    imagely · nextgen galleryFeb 9, 2021

  • CVE-2015-1785
    26Monitor

    In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we

    MediumCVSS 6.5No exploitEPSS 1%

    imagely · nextgen galleryJul 7, 2022

  • NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 1%

    imagely · nextgen galleryMay 5, 2021

  • CVE-2024-5442
    23Monitor

    NextGEN Gallery < 3.59.3 - Admin+ Stored XSS

    MediumCVSS 5.9No exploitEPSS 0%

    imagely · nextgen galleryJul 13, 2024

  • CVE-2015-9537
    21Monitor

    The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thum

    MediumCVSS 5.4No exploitEPSS 1%

    imagely · nextgen galleryNov 26, 2019

  • CVE-2015-9229
    19Monitor

    In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated

    MediumCVSS 4.8No exploitEPSS 1%

    imagely · nextgen gallerySep 12, 2017

  • CVE-2023-3279
    19Monitor

    NextGEN Gallery < 3.39 - Admin+ Local File Inclusion

    MediumCVSS 4.9No exploitEPSS 1%

    imagely · nextgen galleryOct 16, 2023

  • Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.

    MediumCVSS 4.8No exploitEPSS 1%

    imagely · nextgen galleryApr 30, 2018

  • CVE-2024-6393
    19Monitor

    NextGEN Gallery < 3.59.5 - Admin+ Stored XSS

    MediumCVSS 4.8No exploitEPSS 0%

    imagely · nextgen galleryNov 25, 2024

  • WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    imagely · nextgen galleryAug 1, 2024

  • CVE-2024-2744
    17Monitor

    Nextgen Gallery < 3.59.1 - Admin+ Stored XSS

    MediumCVSS 4.3No exploitEPSS 0%

    imagely · nextgen galleryMay 17, 2024