Skip to main content

Software intelligence

Foogallery vulnerabilities

24 tracked advisories · slug foogallery

Important: Foogallery appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

24

Latest advisory

12 June 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

foogallery

Plugin

What this means for Foogallery

This catalog lists 24 known advisories affecting Foogallery. The most recent was published on 12 June 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 12 June 2026

  • Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 30 April 2026

  • FooGallery <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 15 February 2026

Vulnerability types

  • Cross-site scripting18
  • CSRF1

Authentication (inferred from titles)

  • Unauthenticated0
  • Authenticated13
  • Unspecified11

Advisory history

Known Foogallery advisories published by month.

All advisories

1–15 of 24

1 / 2

Check whether your installed version is affected

SiteRespond Defence matches your installed Foogallery version against this catalog when the Defence plugin is connected to your WordPress site.