Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2023-34185

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
Attacker Value
Unknown

CVE-2023-35098

Disclosure Date: June 20, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
Attacker Value
Unknown

CVE-2022-38468

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.
Attacker Value
Unknown

CVE-2015-1785

Disclosure Date: July 07, 2022 (last updated October 07, 2023)
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Attacker Value
Unknown

CVE-2015-1784

Disclosure Date: July 07, 2022 (last updated October 07, 2023)
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Attacker Value
Unknown

CVE-2021-24293

Disclosure Date: May 05, 2021 (last updated November 28, 2024)
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
Attacker Value
Unknown

CVE-2020-35942

Disclosure Date: February 09, 2021 (last updated November 28, 2024)
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Attacker Value
Unknown

CVE-2020-35943

Disclosure Date: February 09, 2021 (last updated November 28, 2024)
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Attacker Value
Unknown

CVE-2013-3684

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Attacker Value
Unknown

CVE-2013-0291

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability