← Vulnerability feed

Vulnerability record · CVE-2015-9228 · published 12 September 2017

CVE-2015-9228: Imagely nextgen gallery unrestricted file upload vulnerability

Imagely · Nextgen Gallery

In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.

8.8 CVSS 3.0 High EPSS 3.7% · top 10.6% CWE-434 · Unrestricted file upload
8.8CVSS 3.0 base score, v2 9.0
3.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-9228 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-3684Imagely nextgen gallery unrestricted file upload vulnerabilityNextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadEPSS 19%9.8CVE-2019-14314Imagely nextgen gallery sql injection vulnerabilityA SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability…EPSS 43%9.8CVE-2016-10889Imagely nextgen gallery sql injection vulnerabilityThe nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.EPSS 1.8%8.8CVE-2023-48328Imagely nextgen gallery cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue af…EPSS 0.27%8.8CVE-2015-1784Imagely nextgen gallery unrestricted file upload vulnerabilityIn nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica…EPSS 2.0%8.8CVE-2020-35942Imagely nextgen gallery cross-site scripting vulnerabilityA Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via se…EPSS 1.4%7.5CVE-2023-3154Imagely nextgen gallery vulnerabilityThe WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `g…EPSS 0.70%7.5CVE-2013-0291Imagely nextgen gallery information exposure vulnerabilityNextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure VulnerabilityEPSS 16%

Source: NIST National Vulnerability Database (record CVE-2015-9228), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.