VYPR
Unrated severityNVD Advisory· Published Mar 12, 2026· Updated Mar 12, 2026

XooGallery Lastest Latest SQL Injection via gal.php gal_id

CVE-2019-25521

Description

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. Attackers can send GET requests to gal.php with malicious gal_id values to extract sensitive database information or modify database contents.

Affected products

1
  • Xooscripts/XooGalleryv5
    Range: *

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.