CVE-2019-25522: Xooscripts Xoogallery
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or modify database contents.
Affected products
- Xooscripts Xoogallery: affected versions not specified
Published 2026-03-12. Last modified 2026-06-17.