Imagely records
27 published records for vendor imagely.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.7%
- Pre-auth RCE
- 2
- With a fix record
- 29.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2019-14314Proof of concept | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.imagely · nextgen gallery · CWE-89 | Critical9.8 | — | 43.4% | Aug 27, 2019 |
45Plan | CVE-2013-3684Proof of concept | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadimagely · nextgen gallery · CWE-434 | Critical9.8 | — | 19.2% | Feb 11, 2020 |
40Plan | CVE-2016-10889No exploit | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.imagely · nextgen gallery · CWE-89 | Critical9.8 | — | 1.8% | Aug 14, 2019 |
36Monitor | CVE-2015-9228No exploit | In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,imagely · nextgen gallery · CWE-434 | High8.8 | — | 3.7% | Sep 12, 2017 |
36Monitor | CVE-2015-1784No exploit | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weimagely · nextgen gallery · CWE-434 | High8.8 | — | 2.0% | Jul 7, 2022 |
35Monitor | CVE-2013-0291Proof of concept | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerabilityimagely · nextgen gallery · CWE-200 | High7.5 | — | 15.6% | Jan 30, 2020 |
35Monitor | CVE-2020-35942No exploit | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusiimagely · nextgen gallery · CWE-79 | High8.8 | — | 1.4% | Feb 9, 2021 |
35Monitor | CVE-2023-48328No exploit | WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)imagely · nextgen gallery · CWE-352 | High8.8 | — | 0.3% | Nov 30, 2023 |
32Monitor | CVE-2024-3097Proof of concept | WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosureimagely · nextgen gallery · CWE-862 | Medium5.3 | — | 38.0% | Apr 9, 2024 |
31Monitor | CVE-2016-6565No exploit | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious fileimagely · nextgen gallery · CWE-98 | High7.5 | — | 2.5% | Jul 13, 2018 |
31Monitor | CVE-2018-7586No exploit | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.imagely · nextgen gallery · CWE-22 | High7.5 | — | 2.0% | Mar 1, 2018 |
30Monitor | CVE-2023-3154No exploit | NextGEN Gallery < 3.39 - Admin+ PHAR Deserializationimagely · nextgen gallery · CWE-502 | High7.5 | — | 0.7% | Oct 16, 2023 |
29Monitor | CVE-2015-9538Weaponized | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.imagely · nextgen gallery · CWE-22 | Medium6.5 | — | 10.1% | Nov 26, 2019 |
28Monitor | CVE-2023-3155No exploit | NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Deleteimagely · nextgen gallery · CWE-552 | High7.2 | — | 0.8% | Oct 16, 2023 |
26Monitor | CVE-2020-35943No exploit | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.imagely · nextgen gallery · CWE-352 | Medium6.5 | — | 0.7% | Feb 9, 2021 |
26Monitor | CVE-2015-1785No exploit | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weimagely · nextgen gallery · CWE-434 | Medium6.5 | — | 0.7% | Jul 7, 2022 |
24Monitor | CVE-2021-24293No exploit | NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)imagely · nextgen gallery · CWE-79 | Medium6.1 | — | 0.9% | May 5, 2021 |
23Monitor | CVE-2024-5442No exploit | NextGEN Gallery < 3.59.3 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Medium5.9 | — | 0.4% | Jul 13, 2024 |
21Monitor | CVE-2015-9537No exploit | The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumimagely · nextgen gallery · CWE-79 | Medium5.4 | — | 1.2% | Nov 26, 2019 |
19Monitor | CVE-2015-9229No exploit | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticatedimagely · nextgen gallery · CWE-79 | Medium4.8 | — | 1.0% | Sep 12, 2017 |
19Monitor | CVE-2023-3279No exploit | NextGEN Gallery < 3.39 - Admin+ Local File Inclusionimagely · nextgen gallery · CWE-22 | Medium4.9 | — | 0.8% | Oct 16, 2023 |
19Monitor | CVE-2018-1000172No exploit | Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.imagely · nextgen gallery · CWE-79 | Medium4.8 | — | 0.6% | Apr 30, 2018 |
19Monitor | CVE-2024-6393No exploit | NextGEN Gallery < 3.59.5 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Medium4.8 | — | 0.5% | Nov 25, 2024 |
19Monitor | CVE-2024-39627No exploit | WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerabilityimagely · nextgen gallery · CWE-79 | Medium4.8 | — | 0.3% | Aug 1, 2024 |
17Monitor | CVE-2024-2744No exploit | Nextgen Gallery < 3.59.1 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Medium4.3 | — | 0.4% | May 17, 2024 |
- CVE-2019-1431452Plan
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.
CriticalCVSS 9.8Proof of conceptEPSS 43%imagely · nextgen galleryAug 27, 2019
- CVE-2013-368445Plan
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
CriticalCVSS 9.8Proof of conceptEPSS 19%imagely · nextgen galleryFeb 11, 2020
- CVE-2016-1088940Plan
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
CriticalCVSS 9.8No exploitEPSS 2%imagely · nextgen galleryAug 14, 2019
- CVE-2015-922836Monitor
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,
HighCVSS 8.8No exploitEPSS 4%imagely · nextgen gallerySep 12, 2017
- CVE-2015-178436Monitor
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we
HighCVSS 8.8No exploitEPSS 2%imagely · nextgen galleryJul 7, 2022
- CVE-2013-029135Monitor
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
HighCVSS 7.5Proof of conceptEPSS 16%imagely · nextgen galleryJan 30, 2020
- CVE-2020-3594235Monitor
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusi
HighCVSS 8.8No exploitEPSS 1%imagely · nextgen galleryFeb 9, 2021
- CVE-2023-4832835Monitor
WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%imagely · nextgen galleryNov 30, 2023
- CVE-2024-309732Monitor
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
MediumCVSS 5.3Proof of conceptEPSS 38%imagely · nextgen galleryApr 9, 2024
- CVE-2016-656531Monitor
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file
HighCVSS 7.5No exploitEPSS 3%imagely · nextgen galleryJul 13, 2018
- CVE-2018-758631Monitor
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
HighCVSS 7.5No exploitEPSS 2%imagely · nextgen galleryMar 1, 2018
- CVE-2023-315430Monitor
NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization
HighCVSS 7.5No exploitEPSS 1%imagely · nextgen galleryOct 16, 2023
- CVE-2015-953829Monitor
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
MediumCVSS 6.5WeaponizedEPSS 10%imagely · nextgen galleryNov 26, 2019
- CVE-2023-315528Monitor
NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete
HighCVSS 7.2No exploitEPSS 1%imagely · nextgen galleryOct 16, 2023
- CVE-2020-3594326Monitor
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.
MediumCVSS 6.5No exploitEPSS 1%imagely · nextgen galleryFeb 9, 2021
- CVE-2015-178526Monitor
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we
MediumCVSS 6.5No exploitEPSS 1%imagely · nextgen galleryJul 7, 2022
- CVE-2021-2429324Monitor
NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%imagely · nextgen galleryMay 5, 2021
- CVE-2024-544223Monitor
NextGEN Gallery < 3.59.3 - Admin+ Stored XSS
MediumCVSS 5.9No exploitEPSS 0%imagely · nextgen galleryJul 13, 2024
- CVE-2015-953721Monitor
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thum
MediumCVSS 5.4No exploitEPSS 1%imagely · nextgen galleryNov 26, 2019
- CVE-2015-922919Monitor
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated
MediumCVSS 4.8No exploitEPSS 1%imagely · nextgen gallerySep 12, 2017
- CVE-2023-327919Monitor
NextGEN Gallery < 3.39 - Admin+ Local File Inclusion
MediumCVSS 4.9No exploitEPSS 1%imagely · nextgen galleryOct 16, 2023
- CVE-2018-100017219Monitor
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.
MediumCVSS 4.8No exploitEPSS 1%imagely · nextgen galleryApr 30, 2018
- CVE-2024-639319Monitor
NextGEN Gallery < 3.59.5 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%imagely · nextgen galleryNov 25, 2024
- CVE-2024-3962719Monitor
WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%imagely · nextgen galleryAug 1, 2024
- CVE-2024-274417Monitor
Nextgen Gallery < 3.59.1 - Admin+ Stored XSS
MediumCVSS 4.3No exploitEPSS 0%imagely · nextgen galleryMay 17, 2024