Unrated severityNVD Advisory· Published Mar 12, 2026· Updated Mar 12, 2026
XooGallery Lastest Latest Multiple SQL Injections via photo.php
CVE-2019-25522
Description
XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or modify database contents.
Affected products
1- Xooscripts/XooGalleryv5Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/46609mitreexploit
- www.vulncheck.com/advisories/xoogallery-lastest-latest-multiple-sql-injections-via-photo-phpmitrethird-party-advisory
News mentions
0No linked articles in our index yet.