NextGEN Gallery SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in NextGEN Gallery versions prior to 4.2.1. This issue allows authenticated attackers with the 'NextGEN Gallery overview' capability, typically assigned to administrators, to inject arbitrary SQL into the 'ORDER BY' clause via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'. The vulnerability arises from a sanitization function in the data mapper layer that employs a character blacklist instead of a whitelist approach, leaving the application open to SQL injection attacks.

Impact

Exploitation of this vulnerability allows for authenticated SQL injection, where an attacker can manipulate SQL queries executed by the application. This could potentially lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations through the database.

Remediation

Users are advised to upgrade to NextGEN Gallery version 4.2.1 or later.

Added: May 20, 2026, 9:18 AM
Updated: May 20, 2026, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
5.4
remediation
7.7
relevance
8.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.