SecAlerts
f

foogallery

Security Risk Profile

29
/100
low

Security Risk Score

Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 20, 2024 to present

9
Total CVEs
1
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
29/100
low

Severity Distribution

Critical
0
High
1
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
Path Traversal
1

Most Affected Products

1. FooPlugins Foogallery Wordpress7
2. FooGallery FooGallery6
3. FooGallery Photo Gallery by FooGallery1
4. FooGallery FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel1
5. FooGallery FooGallery plugin for WordPress1

Recent Vulnerabilities

See more →
CVE-2026-9134
CVSS 6.4EPSS 0%medium

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter

6/13/2026🔧 No Patch
CVE-2025-6068
CVSS 6.4EPSS 0%medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

7/11/2025🔧 No Patch
CVE-2024-12114
CVSS 4.3medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates

3/8/2025
CVE-2024-12119
CVSS 6.4medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Authenticated (Custom+) Stored Cross-Site Scripting via Album Title Size

3/8/2025🔧 No Patch
CVE-2025-22624
CVSS 5.1medium

FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 - Reflected cross-site scripting (XSS)

2/27/2025🔧 No Patch
CVE-2023-6947
CVSS 7.7high

Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal

12/10/2024
CVE-2024-2081
CVSS 6.4medium

FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting

4/9/2024🔧 No Patch
CVE-2024-2471
CVSS 6.4medium

FooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields

4/6/2024
CVE-2024-0604
CVSS 4.8medium

Best WordPress Gallery Plugin – FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings

2/20/2024🔧 No Patch

Monitor foogallery in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

foogallery Security Vulnerabilities & Risk Score | 9 CVEs | SecAlerts - SecAlerts