๐Ÿ” CVE Alert

CVE-2026-9059

UNKNOWN 0.0

NextGEN Gallery - SQL Injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
8th

NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'. The root cause is an insufficient sanitization function ('_clean_column()') in the data mapper layer that uses a character blacklist instead of a whitelist approach. This allows an authenticated attacker with the 'NextGEN Gallery overview' capability (assigned to the Administrator role by default) to inject arbitrary SQL into the 'ORDER BY' clause.

CWE CWE-89
Vendor awesomemotive
Product nextgen gallery
Published May 20, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for awesomemotive nextgen gallery

Be the first to know when new unknown vulnerabilities affecting awesomemotive nextgen gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

awesomemotive / NextGEN Gallery
O < 4.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tenable.com: https://www.tenable.com/security/research/tra-2026-42