Cross-site Scripting Vulnerability in FooPlugins FooGallery Plugin
CVE-2026-25362
5.9MEDIUM
What is CVE-2026-25362?
The FooPlugins FooGallery plugin is exposed to a Stored Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts via web page generation. This flaw affects versions of FooGallery up to and including 3.1.11, potentially compromising user data and triggering unauthorized actions in the browser. Proper input sanitization is vital to mitigate risks associated with this vulnerability.
Affected Version(s)
FooGallery 0 <= 3.1.11