Записи Imagely
27 опубликованных записей вендора imagely.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,7 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 29,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2019-14314Proof of concept | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.imagely · nextgen gallery · CWE-89 | Критическая9,8 | — | 43,4 % | 27 авг. 2019 г. |
45В плане | CVE-2013-3684Proof of concept | NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadimagely · nextgen gallery · CWE-434 | Критическая9,8 | — | 19,2 % | 11 февр. 2020 г. |
40В плане | CVE-2016-10889Эксплойта нет | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.imagely · nextgen gallery · CWE-89 | Критическая9,8 | — | 1,8 % | 14 авг. 2019 г. |
36Наблюдать | CVE-2015-9228Эксплойта нет | In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,imagely · nextgen gallery · CWE-434 | Высокая8,8 | — | 3,7 % | 12 сент. 2017 г. |
36Наблюдать | CVE-2015-1784Эксплойта нет | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weimagely · nextgen gallery · CWE-434 | Высокая8,8 | — | 2,0 % | 7 июл. 2022 г. |
35Наблюдать | CVE-2013-0291Proof of concept | NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerabilityimagely · nextgen gallery · CWE-200 | Высокая7,5 | — | 15,6 % | 30 янв. 2020 г. |
35Наблюдать | CVE-2020-35942Эксплойта нет | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusiimagely · nextgen gallery · CWE-79 | Высокая8,8 | — | 1,4 % | 9 февр. 2021 г. |
35Наблюдать | CVE-2023-48328Эксплойта нет | WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)imagely · nextgen gallery · CWE-352 | Высокая8,8 | — | 0,3 % | 30 нояб. 2023 г. |
32Наблюдать | CVE-2024-3097Proof of concept | WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosureimagely · nextgen gallery · CWE-862 | Средняя5,3 | — | 38,0 % | 9 апр. 2024 г. |
31Наблюдать | CVE-2016-6565Эксплойта нет | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious fileimagely · nextgen gallery · CWE-98 | Высокая7,5 | — | 2,5 % | 13 июл. 2018 г. |
31Наблюдать | CVE-2018-7586Эксплойта нет | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.imagely · nextgen gallery · CWE-22 | Высокая7,5 | — | 2,0 % | 1 мар. 2018 г. |
30Наблюдать | CVE-2023-3154Эксплойта нет | NextGEN Gallery < 3.39 - Admin+ PHAR Deserializationimagely · nextgen gallery · CWE-502 | Высокая7,5 | — | 0,7 % | 16 окт. 2023 г. |
29Наблюдать | CVE-2015-9538Готовый эксплойт | The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.imagely · nextgen gallery · CWE-22 | Средняя6,5 | — | 10,1 % | 26 нояб. 2019 г. |
28Наблюдать | CVE-2023-3155Эксплойта нет | NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Deleteimagely · nextgen gallery · CWE-552 | Высокая7,2 | — | 0,8 % | 16 окт. 2023 г. |
26Наблюдать | CVE-2020-35943Эксплойта нет | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.imagely · nextgen gallery · CWE-352 | Средняя6,5 | — | 0,7 % | 9 февр. 2021 г. |
26Наблюдать | CVE-2015-1785Эксплойта нет | In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the weimagely · nextgen gallery · CWE-434 | Средняя6,5 | — | 0,7 % | 7 июл. 2022 г. |
24Наблюдать | CVE-2021-24293Эксплойта нет | NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)imagely · nextgen gallery · CWE-79 | Средняя6,1 | — | 0,9 % | 5 мая 2021 г. |
23Наблюдать | CVE-2024-5442Эксплойта нет | NextGEN Gallery < 3.59.3 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Средняя5,9 | — | 0,4 % | 13 июл. 2024 г. |
21Наблюдать | CVE-2015-9537Эксплойта нет | The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumimagely · nextgen gallery · CWE-79 | Средняя5,4 | — | 1,2 % | 26 нояб. 2019 г. |
19Наблюдать | CVE-2015-9229Эксплойта нет | In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticatedimagely · nextgen gallery · CWE-79 | Средняя4,8 | — | 1,0 % | 12 сент. 2017 г. |
19Наблюдать | CVE-2023-3279Эксплойта нет | NextGEN Gallery < 3.39 - Admin+ Local File Inclusionimagely · nextgen gallery · CWE-22 | Средняя4,9 | — | 0,8 % | 16 окт. 2023 г. |
19Наблюдать | CVE-2018-1000172Эксплойта нет | Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.imagely · nextgen gallery · CWE-79 | Средняя4,8 | — | 0,6 % | 30 апр. 2018 г. |
19Наблюдать | CVE-2024-6393Эксплойта нет | NextGEN Gallery < 3.59.5 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Средняя4,8 | — | 0,5 % | 25 нояб. 2024 г. |
19Наблюдать | CVE-2024-39627Эксплойта нет | WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerabilityimagely · nextgen gallery · CWE-79 | Средняя4,8 | — | 0,3 % | 1 авг. 2024 г. |
17Наблюдать | CVE-2024-2744Эксплойта нет | Nextgen Gallery < 3.59.1 - Admin+ Stored XSSimagely · nextgen gallery · CWE-79 | Средняя4,3 | — | 0,4 % | 17 мая 2024 г. |
- CVE-2019-1431452В плане
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.
КритическаяCVSS 9,8Proof of conceptEPSS 43 %imagely · nextgen gallery27 авг. 2019 г.
- CVE-2013-368445В плане
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
КритическаяCVSS 9,8Proof of conceptEPSS 19 %imagely · nextgen gallery11 февр. 2020 г.
- CVE-2016-1088940В плане
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %imagely · nextgen gallery14 авг. 2019 г.
- CVE-2015-922836Наблюдать
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter,
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %imagely · nextgen gallery12 сент. 2017 г.
- CVE-2015-178436Наблюдать
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %imagely · nextgen gallery7 июл. 2022 г.
- CVE-2013-029135Наблюдать
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 16 %imagely · nextgen gallery30 янв. 2020 г.
- CVE-2020-3594235Наблюдать
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %imagely · nextgen gallery9 февр. 2021 г.
- CVE-2023-4832835Наблюдать
WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %imagely · nextgen gallery30 нояб. 2023 г.
- CVE-2024-309732Наблюдать
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
СредняяCVSS 5,3Proof of conceptEPSS 38 %imagely · nextgen gallery9 апр. 2024 г.
- CVE-2016-656531Наблюдать
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %imagely · nextgen gallery13 июл. 2018 г.
- CVE-2018-758631Наблюдать
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %imagely · nextgen gallery1 мар. 2018 г.
- CVE-2023-315430Наблюдать
NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %imagely · nextgen gallery16 окт. 2023 г.
- CVE-2015-953829Наблюдать
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
СредняяCVSS 6,5Готовый эксплойтEPSS 10 %imagely · nextgen gallery26 нояб. 2019 г.
- CVE-2023-315528Наблюдать
NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %imagely · nextgen gallery16 окт. 2023 г.
- CVE-2020-3594326Наблюдать
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %imagely · nextgen gallery9 февр. 2021 г.
- CVE-2015-178526Наблюдать
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the we
СредняяCVSS 6,5Эксплойта нетEPSS 1 %imagely · nextgen gallery7 июл. 2022 г.
- CVE-2021-2429324Наблюдать
NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 1 %imagely · nextgen gallery5 мая 2021 г.
- CVE-2024-544223Наблюдать
NextGEN Gallery < 3.59.3 - Admin+ Stored XSS
СредняяCVSS 5,9Эксплойта нетEPSS 0 %imagely · nextgen gallery13 июл. 2024 г.
- CVE-2015-953721Наблюдать
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thum
СредняяCVSS 5,4Эксплойта нетEPSS 1 %imagely · nextgen gallery26 нояб. 2019 г.
- CVE-2015-922919Наблюдать
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated
СредняяCVSS 4,8Эксплойта нетEPSS 1 %imagely · nextgen gallery12 сент. 2017 г.
- CVE-2023-327919Наблюдать
NextGEN Gallery < 3.39 - Admin+ Local File Inclusion
СредняяCVSS 4,9Эксплойта нетEPSS 1 %imagely · nextgen gallery16 окт. 2023 г.
- CVE-2018-100017219Наблюдать
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %imagely · nextgen gallery30 апр. 2018 г.
- CVE-2024-639319Наблюдать
NextGEN Gallery < 3.59.5 - Admin+ Stored XSS
СредняяCVSS 4,8Эксплойта нетEPSS 0 %imagely · nextgen gallery25 нояб. 2024 г.
- CVE-2024-3962719Наблюдать
WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 4,8Эксплойта нетEPSS 0 %imagely · nextgen gallery1 авг. 2024 г.
- CVE-2024-274417Наблюдать
Nextgen Gallery < 3.59.1 - Admin+ Stored XSS
СредняяCVSS 4,3Эксплойта нетEPSS 0 %imagely · nextgen gallery17 мая 2024 г.