Known vulnerabilities in WordPress Gallery Plugin - NextGEN Gallery

Vendor: Imagely
Software CPE: cpe:2.3:a:imagely:nextgen-gallery:*:*:*:*:*:wordpress:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting WordPress Gallery Plugin - NextGEN Gallery WordPress Gallery Plugin - NextGEN Gallery is affected by 7 known vulnerabilities: 3 high, 2 medium, 2 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20435 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-14314
CWE-89 High
No
No
3.2.10 28.08.2019 SB2019082814
#VU19902 - Cross-Site Request Forgery (CSRF)
CWE-352 Medium
No
No
1.8.4 02.08.2019 SB2014080206
#VU19895 - Unrestricted Upload of File with Dangerous Type
CWE-434 High
No
No
2.0.66 02.08.2019 SB2014052001
#VU19886 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
2.0.0 02.08.2019 SB2015020801
#VU19768 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89 High
No
No
2.1.79 02.08.2019 SB2017022703
#VU19671 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1000172
CWE-79 Low
No
No
2.2.45 02.08.2019 SB2018021422
#VU5907 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89 Medium
No
No
- 02.03.2017 SB2017030201