High severity8.2NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2019-25521
CVE-2019-25521
Description
XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. Attackers can send GET requests to gal.php with malicious gal_id values to extract sensitive database information or modify database contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Xooscripts/XooGalleryv5Range: *
- cpe:2.3:a:xooscripts:xoogallery:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/46609nvdExploitVDB Entry
- www.vulncheck.com/advisories/xoogallery-lastest-latest-sql-injection-via-gal-php-gal-idnvdThird Party Advisory
News mentions
0No linked articles in our index yet.