Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

100 known CVEs 300K+ active installs

Scan My Site Free

UNKNOWN: 100
Known Vulnerabilities 100
CVE-2026-1463 UNKNOWN EPSS 0.4%
Published 2026-03-18 · Affected: *
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in
CVE-2025-13641 UNKNOWN EPSS 0.5%
Published 2025-12-18 · Affected: *
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.59.12 via the 'template' shortcode
CVE-2024-3097 UNKNOWN EPSS 1.0%
Published 2024-04-09 · Affected: *
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and inclu
CVE-2024-3097 UNKNOWN EPSS 1.0%
Published 2024-04-09 · Affected: *
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and inclu
CVE-2015-9229 UNKNOWN EPSS 0.6%
Published 2017-09-12 · Affected: <2.1.15
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.79
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.78.1
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.78
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.77
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.76
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.74
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.71
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.33
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.31
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.29
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.27
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.26
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.17
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66.16
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.66
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.65
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.63
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.61
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.59
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.58
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.57
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.40
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.33
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.31
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.30
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.27
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.25
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.23
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.21
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.17
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.14
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.11
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0.7
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.13
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.12
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.11
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.10
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.8
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.7
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.6
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.5
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.3
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.1
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.9.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.5.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.5.1
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.5.2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.8.4
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.8.3
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.8.2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.8.1
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.8.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.7.4
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.7.3
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.7.2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.7.1
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.1.10
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.6.2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.6.1
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.6.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.5.5
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.5.4
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.5.3
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <1.7.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.1.9
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.1.7
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.1.2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-9228 UNKNOWN EPSS 0.9%
Published 2017-09-12 · Affected: <2.1.0
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <1.4.0
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: *
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.33
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.34
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.35
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.36
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.37
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.39
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.40
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.41
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.42
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.43
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.50
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.51
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.52
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.60
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.61
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.62
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.63
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.64
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.70
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.71
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.72
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.73
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param
CVE-2010-1186 UNKNOWN EPSS 0.9%
Published 2010-04-07 · Affected: <0.74
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode param

Is Photo Gallery, Sliders, Proofing and Themes &#8211; NextGEN Gallery running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free