Imagely's vulnerability footprint centers on NextGen Gallery, a widely embedded WordPress gallery plugin that powers image management across a substantial number of websites, despite the vendor's narrow product scope. Vulnerabilities affecting this plugin skew toward serious outcomes and frequently acquire public exploit code, reflecting both the accessibility of WordPress plugins to attackers and the web-application weaknesses inherent to user-facing media handlers. The recurring exposure clusters around input-handling and access-control flaws—including cross-site scripting, cross-site request forgery, arbitrary file upload, path traversal, and SQL injection—that are characteristic of gallery and media-processing plugins where user input drives rendering and file operations. Defenders deploying NextGen Gallery should prioritize timely updates and validate plugin permissions, particularly around file-upload boundaries and template rendering. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imagely over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14314CRITICAL A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker | Aug 27, 2019 | 9.8 | 53 | NO | NO |
CVE-2024-3097MEDIUM The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versi | Apr 9, 2024 | 5.3 | 44 | NO | YES |
CVE-2013-3684CRITICAL NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | Feb 11, 2020 | 9.8 | 44 | NO | YES |
CVE-2013-0291HIGH NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability | Jan 30, 2020 | 7.5 | 41 | NO | YES |
CVE-2015-9538MEDIUM The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. | Nov 26, 2019 | 6.5 | 30 | NO | YES |
CVE-2015-1784HIGH In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie i | Jul 7, 2022 | 8.8 | 29 | NO | NO |
CVE-2016-10889CRITICAL The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | Aug 14, 2019 | 9.8 | 28 | NO | NO |
CVE-2020-35942HIGH A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to | Feb 9, 2021 | 8.8 | 26 | NO | NO |
CVE-2023-48328HIGH Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin | Nov 30, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-7586HIGH In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. | Mar 1, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imagely.
Media articles that mention a CVE ID that affects a product developed by Imagely — matched by CVE ID, not by vendor name.