High severity8.2NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2019-25522
CVE-2019-25522
Description
XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or modify database contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Xooscripts/XooGalleryv5Range: *
- cpe:2.3:a:xooscripts:xoogallery:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/46609nvdExploitVDB Entry
- www.vulncheck.com/advisories/xoogallery-lastest-latest-multiple-sql-injections-via-photo-phpnvdThird Party Advisory
News mentions
0No linked articles in our index yet.