Nextgen Gallery

Vendor:

First CVE: Sep 12, 2017 · Active for 8 years

27
Total CVEs
More Total CVEs than 96% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Nextgen Gallery over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2017
8 years ago
Most Recent CVE
Feb 25, 2025
514 days ago

CVE Severity & Scoring

Nextgen Gallery27 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None13 (48.1%)
Unknown0 (0.0%)
Required14 (51.9%)
Privileges Required
Low5 (18.5%)
High9 (33.3%)
None13 (48.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker
Aug 27, 20199.853NONO
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versi
Apr 9, 20245.344NOYES
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
Feb 11, 20209.844NOYES
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
Jan 30, 20207.541NOYES
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
Nov 26, 20196.530NOYES
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie i
Jul 7, 20228.829NONO
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
Aug 14, 20199.828NONO
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to
Feb 9, 20218.826NONO
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin
Nov 30, 20238.825NONO
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
Mar 1, 20187.523NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.7% of CVEs· 96th percentile
Nuclei
1 CVE
3.7% of CVEs· 97th percentile
ExploitDB
2 CVEs
7.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Nextgen Gallery

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.1.918.83.7%00
2.1.718.83.7%00
2.1.218.83.7%00
2.1.1514.81.0%00
2.1.1018.83.7%00
2.1.018.83.7%00
2.0.7918.83.7%00
2.0.78.118.83.7%00
2.0.7818.83.7%00
2.0.7718.83.7%00
2.0.7618.83.7%00
2.0.7418.83.7%00
2.0.7118.83.7%00
2.0.718.83.7%00
2.0.66.3318.83.7%00
2.0.66.3118.83.7%00
2.0.66.2918.83.7%00
2.0.66.2718.83.7%00
2.0.66.2618.83.7%00
2.0.66.1718.83.7%00