Photo gallery, sliders, proofing and themes – nextgen gallery
This hub aggregates every CVE we track for Photo gallery, sliders, proofing and themes – nextgen gallery, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH2
Monthly trend
0
0
0
1
0
0
0
0
1
0
1
0
0
0
0
1
0
0
1
0
1
0
0
0
2024-092026-08
Latest CVEs
The 7 most recently published vulnerabilities affecting Photo gallery, sliders, proofing and themes – nextgen gallery.
- CVE-2026-6566Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API4.3
- CVE-2026-1463Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion8.8
- CVE-2025-13641Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template'8.8
- CVE-2025-2537Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library6.4
- CVE-2024-5878Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library6.4
- CVE-2024-5020Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library6.4
- CVE-2024-3097WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure5.3
Product normalization is registry-driven with AI assist and human review. How it works