imagely CVE Vulnerabilities & Metrics

Focus on imagely vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About imagely Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with imagely. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total imagely CVEs: 23
Earliest CVE date: 12 Sep 2017, 08:29 UTC
Latest CVE date: 01 Aug 2024, 23:15 UTC

Latest CVE reference: CVE-2024-39627

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -50.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical imagely CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.94

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 10
4.0-6.9 9
7.0-8.9 2
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS imagely CVEs

These are the five CVEs with the highest CVSS scores for imagely, sorted by severity first and recency.

All CVEs for imagely

CVE-2024-39627 imagely vulnerability CVSS: 0 01 Aug 2024, 23:15 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Gallery allows Stored XSS.This issue affects NextGEN Gallery: from n/a through 3.59.3.

CVE-2024-3097 imagely vulnerability CVSS: 0 09 Apr 2024, 19:15 UTC

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.

CVE-2023-48328 imagely vulnerability CVSS: 0 30 Nov 2023, 16:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.

CVE-2023-3279 imagely vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks

CVE-2023-3155 imagely vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

CVE-2023-3154 imagely vulnerability CVSS: 0 16 Oct 2023, 20:15 UTC

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

CVE-2022-38468 imagely vulnerability CVSS: 0 01 Mar 2023, 14:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration.

CVE-2015-1785 imagely vulnerability CVSS: 4.3 07 Jul 2022, 13:15 UTC

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

CVE-2015-1784 imagely vulnerability CVSS: 6.5 07 Jul 2022, 13:15 UTC

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

CVE-2021-24293 imagely vulnerability CVSS: 4.3 05 May 2021, 19:15 UTC

In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.

CVE-2020-35943 imagely vulnerability CVSS: 4.3 09 Feb 2021, 18:15 UTC

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

CVE-2020-35942 imagely vulnerability CVSS: 6.8 09 Feb 2021, 18:15 UTC

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

CVE-2013-3684 imagely vulnerability CVSS: 10.0 11 Feb 2020, 18:15 UTC

NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

CVE-2013-0291 imagely vulnerability CVSS: 5.0 30 Jan 2020, 13:15 UTC

NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability

CVE-2015-9538 imagely vulnerability CVSS: 4.0 26 Nov 2019, 15:15 UTC

The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

CVE-2015-9537 imagely vulnerability CVSS: 3.5 26 Nov 2019, 15:15 UTC

The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.

CVE-2019-14314 imagely vulnerability CVSS: 7.5 27 Aug 2019, 16:15 UTC

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

CVE-2016-10889 imagely vulnerability CVSS: 7.5 14 Aug 2019, 15:15 UTC

The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.

CVE-2016-6565 imagely vulnerability CVSS: 6.0 13 Jul 2018, 20:29 UTC

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).

CVE-2018-1000172 imagely vulnerability CVSS: 3.5 30 Apr 2018, 22:29 UTC

Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.

CVE-2018-7586 imagely vulnerability CVSS: 5.0 01 Mar 2018, 22:29 UTC

In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.

CVE-2015-9229 imagely vulnerability CVSS: 3.5 12 Sep 2017, 22:29 UTC

In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.

CVE-2015-9228 imagely vulnerability CVSS: 9.0 12 Sep 2017, 08:29 UTC

In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.