Unrated severityNVD Advisory· Published Mar 12, 2026· Updated Mar 12, 2026
XooGallery Lastest Latest SQL Injection via cat.php
CVE-2019-25523
Description
XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to cat.php with malicious cat_id values to bypass authentication, extract sensitive data, or modify database contents.
Affected products
2- Xooscripts/XooGalleryv5Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/46609mitreexploit
- www.vulncheck.com/advisories/xoogallery-lastest-latest-sql-injection-via-cat-phpmitrethird-party-advisory
News mentions
0No linked articles in our index yet.