What is CVE-2026-28141?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in NextGEN Gallery plugin versions 4.2.3 and earlier. This flaw could allow an attacker to execute arbitrary code in a user's browser. Users should update to the latest version immediately.
Azərbaycanca: NextGEN Gallery plagininin 4.2.3 və daha əvvəlki versiyalarında autentifikasiya olunmamış Cross Site Scripting (XSS) zəifliyi aşkarlanıb. Bu zəiflik təcavüzkara istifadəçi brauzerində ixtiyari kod icra etməyə imkan verə bilər. Plagindən istifadə edənlər dərhal son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the NextGEN Gallery plugin are affected by CVE-2026-28141?
CVE-2026-28141 affects NextGEN Gallery plugin versions 4.2.3 and earlier.
What does the CVE-2026-28141 vulnerability allow an attacker to do?
This vulnerability could allow an attacker to execute arbitrary code in a user's browser.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.