Vulnerabilities > Imagely

DATE CVE VULNERABILITY TITLE RISK
2018-03-01 CVE-2018-7586 Path Traversal vulnerability in Imagely Nextgen Gallery
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
network
low complexity
imagely CWE-22
7.5
2017-09-12 CVE-2015-9229 Cross-site Scripting vulnerability in Imagely Nextgen Gallery 2.1.15
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
network
low complexity
imagely CWE-79
4.8
2017-09-12 CVE-2015-9228 Unrestricted Upload of File with Dangerous Type vulnerability in Imagely Nextgen Gallery
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
network
low complexity
imagely CWE-434
8.8