Imagely

Nextgen Gallery

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 01.03.2023 14:15:15
  • Zuletzt bearbeitet 21.11.2024 07:16:32

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 07.07.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 02:26:07

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of securi...

Exploit
  • EPSS 1.18%
  • Veröffentlicht 07.07.2022 13:15:07
  • Zuletzt bearbeitet 21.11.2024 02:26:07

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of securi...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 05.05.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:52:46

In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 09.02.2021 18:15:45
  • Zuletzt bearbeitet 21.11.2024 05:28:34

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.02.2021 18:15:44
  • Zuletzt bearbeitet 21.11.2024 05:28:33

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protect...

  • EPSS 42.63%
  • Veröffentlicht 11.02.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 01:54:07

NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

Exploit
  • EPSS 30.95%
  • Veröffentlicht 30.01.2020 13:15:14
  • Zuletzt bearbeitet 21.11.2024 01:47:14

NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability

Exploit
  • EPSS 70.25%
  • Veröffentlicht 26.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:40:52

The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 26.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:40:52

The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.