Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2015-9537

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
Attacker Value
Unknown

CVE-2015-9538

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Attacker Value
Unknown

CVE-2016-10889

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
0
Attacker Value
Unknown

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may ex…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).
0
Attacker Value
Unknown

CVE-2018-1000172

Disclosure Date: April 30, 2018 (last updated November 26, 2024)
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.
0
Attacker Value
Unknown

CVE-2018-7586

Disclosure Date: March 01, 2018 (last updated November 26, 2024)
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
0
Attacker Value
Unknown

CVE-2015-9229

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
Attacker Value
Unknown

CVE-2015-9228

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
0
Attacker Value
Unknown

CVE-2010-1186

Disclosure Date: April 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
0
Attacker Value
Unknown

CVE-2008-7175

Disclosure Date: September 08, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.
0