VendorsFooPluginsfoogalleryall versions
Vulnerabilities

FooPlugins FooGallery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2023-44233
WordPress FooGallery Plugin <= 2.2.44 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-10-06 · Modified
8.8EPSS 0.002
CVE-2023-6947
Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
Published 2024-12-10 · Analyzed
7.7EPSS 0.008
CVE-2023-29439
WordPress FooGallery Plugin <= 2.2.35 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-16 · Modified
7.1EPSS 0.017
CVE-2023-44244
WordPress FooGallery Plugin <= 2.2.44 is vulnerable to Cross Site Scripting (XSS)
Published 2023-10-02 · Modified
7.1EPSS 0.004
CVE-2024-2081
FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting
Published 2024-04-09 · Modified
6.4EPSS 0.006
CVE-2024-2122
FooGallery <= 2.4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Custom URL
Published 2024-06-14 · Modified
6.4EPSS 0.005
CVE-2023-6747
FooGallery Premium <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-01-03 · Modified
6.4EPSS 0.004
CVE-2024-2471
FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields
Published 2024-04-06 · Modified
6.4EPSS 0.003
CVE-2024-12119
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size
Published 2025-03-08 · Analyzed
6.4EPSS 0.003
CVE-2025-6068
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Published 2025-07-11 · Analyzed
6.4EPSS 0.002
CVE-2024-2762
FooGallery < 2.4.15 - Author+ Stored XSS
Published 2024-06-13 · Modified
6.3EPSS 0.004
CVE-2021-24357
FooGallery < 2.0.35 - Authenticated Stored Cross-Site Scripting
Published 2021-06-14 · Modified
5.4EPSS 0.006
CVE-2019-20182
The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
Published 2020-01-09 · Modified
4.8EPSS 0.007
CVE-2024-0604
Best WordPress Gallery Plugin – FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings
Published 2024-02-20 · Modified
4.8EPSS 0.006
CVE-2024-12114
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates
Published 2025-03-08 · Analyzed
4.3EPSS 0.003