Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
2010-04-07T15:30:00.437
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | alex_rabe | nextgen_gallery | ≤ 1.5.1 | Yes |
Application | alex_rabe | nextgen_gallery | 0.33 | Yes |
Application | alex_rabe | nextgen_gallery | 0.34 | Yes |
Application | alex_rabe | nextgen_gallery | 0.35 | Yes |
Application | alex_rabe | nextgen_gallery | 0.36 | Yes |
Application | alex_rabe | nextgen_gallery | 0.37 | Yes |
Application | alex_rabe | nextgen_gallery | 0.39 | Yes |
Application | alex_rabe | nextgen_gallery | 0.40 | Yes |
Application | alex_rabe | nextgen_gallery | 0.41 | Yes |
Application | alex_rabe | nextgen_gallery | 0.42 | Yes |
Application | alex_rabe | nextgen_gallery | 0.43 | Yes |
Application | alex_rabe | nextgen_gallery | 0.50 | Yes |
Application | alex_rabe | nextgen_gallery | 0.51 | Yes |
Application | alex_rabe | nextgen_gallery | 0.52 | Yes |
Application | alex_rabe | nextgen_gallery | 0.60 | Yes |
Application | alex_rabe | nextgen_gallery | 0.61 | Yes |
Application | alex_rabe | nextgen_gallery | 0.62 | Yes |
Application | alex_rabe | nextgen_gallery | 0.63 | Yes |
Application | alex_rabe | nextgen_gallery | 0.64 | Yes |
Application | alex_rabe | nextgen_gallery | 0.70 | Yes |
Application | alex_rabe | nextgen_gallery | 0.71 | Yes |
Application | alex_rabe | nextgen_gallery | 0.72 | Yes |
Application | alex_rabe | nextgen_gallery | 0.73 | Yes |
Application | alex_rabe | nextgen_gallery | 0.74 | Yes |
Application | alex_rabe | nextgen_gallery | 0.80 | Yes |
Application | alex_rabe | nextgen_gallery | 0.81 | Yes |
Application | alex_rabe | nextgen_gallery | 0.82 | Yes |
Application | alex_rabe | nextgen_gallery | 0.83 | Yes |
Application | alex_rabe | nextgen_gallery | 0.90 | Yes |
Application | alex_rabe | nextgen_gallery | 0.91 | Yes |
Application | alex_rabe | nextgen_gallery | 0.92 | Yes |
Application | alex_rabe | nextgen_gallery | 0.93 | Yes |
Application | alex_rabe | nextgen_gallery | 0.94 | Yes |
Application | alex_rabe | nextgen_gallery | 0.95 | Yes |
Application | alex_rabe | nextgen_gallery | 0.96 | Yes |
Application | alex_rabe | nextgen_gallery | 0.97 | Yes |
Application | alex_rabe | nextgen_gallery | 0.98 | Yes |
Application | alex_rabe | nextgen_gallery | 0.99 | Yes |
Application | alex_rabe | nextgen_gallery | 1.0.0 | Yes |
Application | alex_rabe | nextgen_gallery | 1.0.1 | Yes |
Application | alex_rabe | nextgen_gallery | 1.0.2 | Yes |
Application | alex_rabe | nextgen_gallery | 1.1.0 | Yes |
Application | alex_rabe | nextgen_gallery | 1.2.0 | Yes |
Application | alex_rabe | nextgen_gallery | 1.2.1 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.0 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.1 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.2 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.3 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.4 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.5 | Yes |
Application | alex_rabe | nextgen_gallery | 1.3.6 | Yes |
Application | alex_rabe | nextgen_gallery | 1.4.0 | Yes |
Application | alex_rabe | nextgen_gallery | 1.4.1 | Yes |
Application | alex_rabe | nextgen_gallery | 1.4.2 | Yes |
Application | alex_rabe | nextgen_gallery | 1.4.3 | Yes |
Application | alex_rabe | nextgen_gallery | 1.5.0 | Yes |
Application | wordpress | wordpress | * | No |