Known Vulnerabilities for Fancybox by Fancybox Project
Listed below are 1 of the newest known vulnerabilities associated with "Fancybox" by "Fancybox Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-52707 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firelight Firelight Lig... | Not Provided | 2025-06-20 | 2026-04-01 |
| CVE-2025-28935 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in puzich Fancybox Plus fa... | Not Provided | 2025-03-26 | 2026-04-01 |
| CVE-2025-26591 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam WP fancybox w... | Not Provided | 2025-07-04 | 2026-04-01 |
| CVE-2025-23594 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uzzal Mondal Google Map... | Not Provided | 2025-02-03 | 2026-04-01 |
| CVE-2024-54401 json | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Turcu Advanced Fancybox advanced-fancybox allows Stored XSS.This i... | Not Provided | 2024-12-16 | 2026-04-01 |
| CVE-2024-50460 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firelight Firelight Lig... | Not Provided | 2024-10-28 | 2026-04-01 |
| CVE-2024-5020 json | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript lib... | Not Provided | 2024-12-04 | 2026-04-08 |
| CVE-2023-5465 json | The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and... | Not Provided | 2023-11-22 | 2026-04-08 |
| CVE-2015-1494 json | The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers... | 4.3 - MEDIUM | 2015-02-17 | 2021-09-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fancybox Project | Fancybox | 3.0.2 |