plugin

Nextcellent Gallery Nextgen Legacy Vulnerabilities

2 known security issues reported for the Nextcellent Gallery Nextgen Legacy WordPress plugin. Most recent disclosed Jun 6, 2022.

2 medium

Running Nextcellent Gallery Nextgen Legacy on your site? Check whether your installed version is affected.

Scan your site free

NextCellent Gallery <= 1.9.35 - Authenticated (Admin+) Cross-Site Scripting

medium

The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS:
4.8
Affected:
up to 1.9.35
Fix:
No patched version reported
Disclosed:
Jun 6, 2022

CVE-2022-1971 on NVD →

NextCellent Gallery < 1.9.18 - Stored Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & T...

CVSS:
5.5
Affected:
up to 1.9.18
Fixed in:
1.9.18
Disclosed:
Apr 29, 2014

CVE-2014-3123 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database