CVE-2018-1000172: Imagely NextGen Gallery

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.

Affected products

  • Imagely NextGen Gallery: up to and including 2.2.30

Published 2018-04-30. Last modified 2026-06-17.