Skip to content

CVE-2014-3123

Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0024 (0.2%)
Percentil: 47.6%
EPSS: 2026-05-06

Afecta

wpgetready:nextcellent_gallery

Descripción técnica

Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.

Publicada: 8/5/2014, 14:29:15
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo