CVE-2010-1186

NextGEN Gallery <1.5.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Alejandro Rodriguez · textwebappsphp
https://www.exploit-db.com/exploits/12098

Scores

EPSS 0.0081
EPSS Percentile 74.0%

Classification

CWE
CWE-79
Status published

Affected Products (50)

alex_rabe/nextgen_gallery < 1.5.1
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
alex_rabe/nextgen_gallery
... and 35 more

Timeline

Published Apr 07, 2010
Tracked Since Feb 18, 2026