Pricing
Case studies
Login
Start trial
NextGEN Gallery
Syed Balkhi
Developer
4.1.2
Latest version
400,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
38 patched
2 Mitigation rules
WordPress Photo Gallery, Sliders, Proofing and Themes - NextGEN Gallery plugin <= 4.0.4 - Authenticated (Author+) Local File Inclusion vulnerability
<= 4.0.4
19/03/2026
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library vulnerability
<= 3.59.11
31/12/2025
Authenticated (Contributor+) Local File Inclusion via 'template' vulnerability
<= 3.59.12
17/12/2025
Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library
<= 3.59.4
19/05/2025
Admin+ Stored XSS vulnerability
< 3.59.9
25/02/2025
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
<= 3.59.4
03/12/2024
Admin+ Stored XSS vulnerability
< 3.59.5
25/11/2024
Cross Site Scripting (XSS) vulnerability
<= 3.59.3
22/07/2024
Admin+ Stored XSS vulnerability
< 3.59.3
15/07/2024
Admin+ Stored XSS vulnerability
< 3.59.1
17/05/2024
Missing Authorization to Unauthenticated Information Disclosure vulnerability
<= 3.59
08/04/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.37
23/11/2023
Admin+ Local File Inclusion vulnerability
< 3.39
17/10/2023
Admin+ Arbitrary File Read and Delete vulnerability
< 3.39
17/10/2023
Admin+ PHAR Deserialization vulnerability
< 3.39
17/10/2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.3.6
19/07/2023
Cross-Site Request Forgery (CSRF)
<= 3.28
14/02/2023
Cross-Site Request Forgery (CSRF) vulnerability leading to file upload
<= 3.4.7
08/02/2021
Cross-Site Request Forgery (CSRF) leading to XSS and RCE via file upload and LFI
<= 3.4.7
08/02/2021
SQL Injection vulnerability
<= 3.2.8
27/08/2019
Authenticated Option Update vulnerability (Fremius Library security issue)
<= 3.1.6
02/03/2019
Sensitive Information Disclosure
<= 2.2.46
02/03/2018
Authenticated Remote Code Execution (RCE) Vulnerability
2.1.59
28/11/2016
Authenticated Path Traversal
<= 2.1.7
07/10/2015
Arbitrary File Upload
<= 2.0.63
15/05/2015
Directory Traversal
<= 2.0.0
15/05/2015
Cross Site Scripting
<= 1.9.7
15/05/2015
Full Path Disclosure
<= 1.9.11
15/05/2015
Stored XSS
<= 1.9.5
15/05/2015
Multiple XSS
<= 1.9.0
15/05/2015
Multiple Vulnerabilities
<= 1.8.3
15/05/2015
Full Path Disclosure
<= 1.7.3
15/05/2015
Directory Traversal
<= 2.0.0
19/02/2014
Arbitrary File Upload
<= 1.9.12
12/06/2013
Path Disclosure Vulnerability
<= 1.9.11
14/02/2013
Cross Site Scripting
<= 1.9.10
08/01/2013
XSS Vulnerability
<= 1.5.1
06/04/2010
XSS
<= 0.96
07/09/2009