Extension WordPress

Vulnérabilités Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel, page 2

Cette page rassemble les failles publiées pour Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
0Critiques
24Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

24 fiches

CVE-2021-24357 Moyenne · 6,4
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 2.0.34 – Stored Cross-Site Scripting

In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery…

Versions affectées

[*, 2.0.35)

Correctif

2.0.35

Publication

31/05/2021

Vulnérabilité Élevée · 8,3
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

FooGallery <= 1.9.24 – Authenticated Cross-Site Scripting

The FooGallery plugin for WordPress is vulnerable to Cross-Site Scripting via the image title and caption parameters in the gallery media upload editor in versions up to, and including, 1.9.24 due to insufficient input sanitization and output escaping.…

Versions affectées

[*, 1.9.25)

Correctif

1.9.25

Publication

04/05/2020

Vulnérabilité Élevée · 8,8
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

[*, 1.6.17)

Correctif

1.6.17

Publication

25/02/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités