Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Imagely

First CVE: Sep 12, 2017Active for: 9 yearsTotal CVEs: 27
42.5
VTI Score
High

Imagely's vulnerability footprint centers on NextGen Gallery, a widely embedded WordPress gallery plugin that powers image management across a substantial number of websites, despite the vendor's narrow product scope. Vulnerabilities affecting this plugin skew toward serious outcomes and frequently acquire public exploit code, reflecting both the accessibility of WordPress plugins to attackers and the web-application weaknesses inherent to user-facing media handlers. The recurring exposure clusters around input-handling and access-control flaws—including cross-site scripting, cross-site request forgery, arbitrary file upload, path traversal, and SQL injection—that are characteristic of gallery and media-processing plugins where user input drives rendering and file operations. Defenders deploying NextGen Gallery should prioritize timely updates and validate plugin permissions, particularly around file-upload boundaries and template rendering. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Imagely over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2017
8 years ago
Most Recent CVE
Feb 25, 2025
514 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14314CRITICAL
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker
Aug 27, 20199.853NONO
CVE-2024-3097MEDIUM
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versi
Apr 9, 20245.344NOYES
CVE-2013-3684CRITICAL
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Feb 11, 20209.844NOYES
CVE-2013-0291HIGH
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
Jan 30, 20207.541NOYES
CVE-2015-9538MEDIUM
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Nov 26, 20196.530NOYES
CVE-2015-1784HIGH
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie i
Jul 7, 20228.829NONO
CVE-2016-10889CRITICAL
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
Aug 14, 20199.828NONO
CVE-2020-35942HIGH
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to
Feb 9, 20218.826NONO
CVE-2023-48328HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin
Nov 30, 20238.825NONO
CVE-2018-7586HIGH
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
Mar 1, 20187.523NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
52%
33%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None13 (48.1%)
Unknown0 (0.0%)
Required14 (51.9%)
Privileges Required
Low5 (18.5%)
High9 (33.3%)
None13 (48.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.7% of CVEs· 98th percentile
Nuclei
1 CVE
3.7% of CVEs· 95th percentile
ExploitDB
2 CVEs
7.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Imagely.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Imagely — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Imagely's Products

View all 6 CNAs →

Top CWEs