VYPR

NextGEN Gallery

by NextGEN Gallery

CVEs (1)

  • CVE-2026-9059CriMay 20, 2026
    risk 0.60cvss epss 0.00

    NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'. The root cause is an insufficient sanitization function ('_clean_column()') in the data…