Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.
2009-09-08T10:30:01.563
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | alex_rabe | nextgen_gallery | ≤ 0.96 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.33 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.34 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.35 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.36 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.37 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.39 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.40 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.41 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.42 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.43 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.50 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.51 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.52 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.60 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.61 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.62 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.63 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.64 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.70 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.71 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.72 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.73 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.74 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.80 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.81 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.82 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.83 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.90 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.91 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.92 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.93 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.94 | Yes |
| Application | alex_rabe | nextgen_gallery | 0.95 | Yes |
| Application | wordpress | wordpress | * | No |