Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2021-24293

Disclosure Date: May 05, 2021 (last updated November 28, 2024)
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
Attacker Value
Unknown

CVE-2020-35942

Disclosure Date: February 09, 2021 (last updated November 28, 2024)
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Attacker Value
Unknown

CVE-2020-35943

Disclosure Date: February 09, 2021 (last updated November 28, 2024)
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Attacker Value
Unknown

CVE-2013-3684

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Attacker Value
Unknown

CVE-2013-0291

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
Attacker Value
Unknown

CVE-2015-9537

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
Attacker Value
Unknown

CVE-2015-9538

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Attacker Value
Unknown

CVE-2016-10889

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
0
Attacker Value
Unknown

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may ex…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).
0
Attacker Value
Unknown

CVE-2018-1000172

Disclosure Date: April 30, 2018 (last updated November 26, 2024)
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.
0