Fooplugins
Fooplugins Foogallery: vulnerabilidades y CVE
Fooplugins Foogallery tiene 20 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85414 | Media (6.4) | 0.42% | — | 5 sept 2026 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and… |
| CVE-2026-9134 | Media (6.4) | 0.33% | — | 13 jun 2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event… |
| CVE-2026-25363 | Media (4.3) | 0.19% | — | 19 feb 2026 | Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11. |
| CVE-2026-25362 | Media (5.9) | 0.17% | — | 19 feb 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGallery: from n/a through <= 3.1.11. |
| CVE-2025-6068 | Media (5.4) | 0.23% | — | 11 jul 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & `data-caption-description` HTML… |
| CVE-2024-12119 | Media (5.4) | 0.27% | — | 8 mar 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up… |
| CVE-2024-12114 | Media (4.3) | 0.32% | — | 8 mar 2025 | The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the… |
| CVE-2025-22624 | Media (5.1) | 0.42% | — | 27 feb 2025 | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 was found to be vulnerable. The web application dynamically generates web content without validating the source of the… |
| CVE-2023-6947 | Alta (7.7) | 0.76% | — | 10 dic 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor… |
| CVE-2024-2122 | Media (5.4) | 0.47% | — | 14 jun 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to insufficient input… |
| CVE-2024-2762 | Media (5.4) | 0.37% | — | 13 jun 2024 | The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users… |
| CVE-2024-2081 | Media (5.4) | 0.60% | — | 9 abr 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to… |
| CVE-2024-2471 | Media (5.4) | 0.34% | — | 6 abr 2024 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and… |
| CVE-2024-0604 | Media (4.8) | 0.62% | — | 29 feb 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and… |
| CVE-2023-6747 | Media (5.4) | 0.40% | — | 3 ene 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, and including, 2.3.3 due to insufficient input… |
| CVE-2023-44233 | Alta (8.8) | 0.22% | — | 6 oct 2023 | Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin – FooGallery plugin <= 2.2.44 versions. |
| CVE-2023-44244 | Media (6.1) | 0.35% | — | 2 oct 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.44 versions. |
| CVE-2023-29439 | Media (6.1) | 1.7% | — | 16 may 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. |
| CVE-2021-24357 | Media (5.4) | 0.62% | — | 14 jun 2021 | In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where… |
| CVE-2019-20182 | Media (4.8) | 0.72% | — | 9 ene 2020 | The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.