Unrated severityNVD Advisory· Published Mar 12, 2026· Updated Mar 12, 2026
XooGallery Lastest Latest SQL Injection via gal.php gal_id
CVE-2019-25521
Description
XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. Attackers can send GET requests to gal.php with malicious gal_id values to extract sensitive database information or modify database contents.
Affected products
1- Xooscripts/XooGalleryv5Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/46609mitreexploit
- www.vulncheck.com/advisories/xoogallery-lastest-latest-sql-injection-via-gal-php-gal-idmitrethird-party-advisory
News mentions
0No linked articles in our index yet.