Vulnerabilities > Imagely > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-48328 Cross-Site Request Forgery (CSRF) vulnerability in Imagely Nextgen Gallery
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
network
low complexity
imagely CWE-352
8.8
2023-10-16 CVE-2023-3154 Unspecified vulnerability in Imagely Nextgen Gallery
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
network
low complexity
imagely
7.5
2023-10-16 CVE-2023-3155 Files or Directories Accessible to External Parties vulnerability in Imagely Nextgen Gallery
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
network
low complexity
imagely CWE-552
7.2
2019-08-27 CVE-2019-14314 SQL Injection vulnerability in Imagely Nextgen Gallery
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress.
network
low complexity
imagely CWE-89
7.5
2019-08-14 CVE-2016-10889 SQL Injection vulnerability in Imagely Nextgen Gallery
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
network
low complexity
imagely CWE-89
7.5