| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-1463 | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion | smub | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | High | 8.8 | 2026-03-18 16:26:27 | Deep Dive |
| CVE-2025-13641 | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template' | smub | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | High | 8.8 | 2025-12-18 09:21:29 | Deep Dive |
| CVE-2025-53224 | WordPress NextGEN Gallery Search Plugin <= 2.12 - Cross Site Scripting (XSS) Vulnerability | Koen Schuit | NextGEN Gallery Search | High | 7.1 | 2025-08-28 12:37:21 | Deep Dive |
| CVE-2025-7641 | Assistant for NextGEN Gallery <= 1.0.9 - Unauthenticated Arbitrary Directory Deletion | 48hmorris | Assistant for NextGEN Gallery | High | 7.5 | 2025-08-15 08:25:38 | Deep Dive |
| CVE-2025-2537 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library | wpdevart | YouTube Embed, Playlist and Popup by WpDevArt | Medium | 6.4 | 2025-07-03 12:23:09 | Deep Dive |
| CVE-2024-5878 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library | aknieriem | Simplelightbox | Medium | 6.4 | 2025-05-20 07:22:30 | Deep Dive |
| CVE-2025-28869 | WordPress NextGEN Gallery Voting plugin <= 2.7.6 - Reflected Cross Site Scripting (XSS) vulnerability | shauno | NextGEN Gallery Voting | High | 7.1 | 2025-03-26 14:24:22 | Deep Dive |
| CVE-2025-25091 | WordPress NextGen Cooliris Gallery plugin <= 0.7 - Cross Site Scripting (XSS) vulnerability | zackdesign | NextGen Cooliris Gallery | Medium | 6.5 | 2025-02-07 10:11:26 | Deep Dive |
| CVE-2024-5020 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | extendthemes | Colibri Page Builder | Medium | 6.4 | 2024-12-04 08:22:47 | Deep Dive |
| CVE-2024-39627 | WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability | Imagely | NextGEN Gallery | Medium | 5.9 | 2024-08-01 22:30:48 | Deep Dive |
| CVE-2024-2744 | Nextgen Gallery < 3.59.1 - Admin+ Stored XSS | Unknown | NextGEN Gallery | 中危 | - | 2024-05-17 06:00:02 | Deep Dive |
| CVE-2024-3097 | WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure | smub | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | Medium | 5.3 | 2024-04-09 18:58:59 | Deep Dive |
| CVE-2023-48328 | WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF) | Imagely | WordPress Gallery Plugin – NextGEN Gallery | Medium | 4.3 | 2023-11-30 16:05:37 | Deep Dive |
| CVE-2022-38468 | WordPress NextGEN Gallery Plugin <= 3.28 is vulnerable to Cross Site Request Forgery (CSRF) | Imagely | WordPress Gallery Plugin – NextGEN Gallery | Medium | 4.3 | 2023-03-01 13:02:02 | Deep Dive |
| CVE-2015-1784 | WordPress plugin nextgen-galery 代码问题漏洞 | - | nextgen-gallery | 高危 | - | 2022-07-07 12:34:24 | Deep Dive |
| CVE-2015-1785 | WordPress plugin nextgen-galery 跨站请求伪造漏洞 | - | nextgen-gallery | 中危 | - | 2022-07-07 12:34:19 | Deep Dive |
| CVE-2022-1971 | NextCellent Gallery <= 1.9.35 - Admin+ Stored XSS | Unknown | NextCellent Gallery – NextGEN Legacy | 中危 | - | 2022-06-27 08:59:02 | Deep Dive |
| CVE-2021-24293 | NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS) | Unknown | NextGen Gallery Pro | 中危 | - | 2021-05-05 18:28:48 | Deep Dive |
| CVE-2013-0291 | WordPress NextGEN Gallery 信息泄露漏洞 | NextGEN Gallery Plugin authors | NextGEN Gallery Plugin | 高危 | - | 2020-01-30 13:00:16 | Deep Dive |
| CVE-2016-6565 | The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 may execute code from an uploaded malicious file | Imagely | NextGen Gallery plugin | 高危 | - | 2018-07-13 20:00:00 | Deep Dive |